8.7

CVSS4.0

CVE-2024-55946 - Playloom Engine Data Storage Vulnerability

Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage, specifically when using the collaboration features. When collaborating with another user, they may have access to personal information you have enter…

πŸ“… Published: Dec. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-12632 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-55956. Reason: This candidate is a duplicate of CVE-2024-55956. Notes: All CVE users should reference CVE-2024-55956 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Dec. 13, 2024, 8:37 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 9:15 p.m.

6.9

CVSS4.0

CVE-2024-55890 - D-Tale allows Remote Code Execution through the Custom Filter Input

D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability…

πŸ“… Published: Dec. 13, 2024, 6 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-47892 - GPU DDK - UAF of kernel memory in PMRUnlockPhysAddressesOSMem for on-demand non-4KB PMRs in system …

Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

πŸ“… Published: Dec. 13, 2024, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-46971 - GPU DDK - UAF of memory in PMRUnlockSysPhysAddressesLocalMem for on-demand PMRs on PCI (LMA) systems

Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

πŸ“… Published: Dec. 13, 2024, 5:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-55887 - Ucum-java has an XXE vulnerability in XML parsing

Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts u…

πŸ“… Published: Dec. 13, 2024, 4:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-55661 - Laravel Pulse Allows Remote Code Execution via Unprotected Query Method

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in Laravel Pulse prior to version 1.3.1 that could allow remote code execution through the public `remember()` method in the `Laravel\Pulse\Livewire\Conce…

πŸ“… Published: Dec. 13, 2024, 4:04 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 6:15 p.m.

7.9

CVSS3.1

CVE-2024-54139 - Combodo iTop vulnerable to XSS leading to CSRF breach on _table_id parameter

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scripting vulnerability that can lead to cross-site request forgery on the `_table_id` parameter. Versions 2.7.11, 3.1.2, and 3.2.0 contain a patch for the…

πŸ“… Published: Dec. 13, 2024, 3:59 p.m. πŸ”„ Last Modified: March 11, 2025, 4:44 p.m.

5.3

CVSS3.1

CVE-2024-9945 - Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0

An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.

πŸ“… Published: Dec. 13, 2024, 3:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-54351 - WordPress Fancy Roller Scroller plugin <= 1.4.0 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Thomas K Landis Fancy Roller Scroller fancy-roller-scroller allows Stored XSS.This issue affects Fancy Roller Scroller: from n/a through <= 1.4.0.

πŸ“… Published: Dec. 13, 2024, 2:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.
Total resulsts: 349182
Page 7467 of 34,919
Β« previous page Β» next page
Filters