9.1

CVSS3.1

CVE-2024-55879 - XWiki allows RCE from script right in configurable sections

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availab…

📅 Published: Dec. 12, 2024, 7:17 p.m. 🔄 Last Modified: April 30, 2025, 4:01 p.m.

10

CVSS3.1

CVE-2024-55877 - XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMac…

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity…

📅 Published: Dec. 12, 2024, 7:13 p.m. 🔄 Last Modified: April 30, 2025, 4:02 p.m.

6.5

CVSS3.1

CVE-2024-49071 - Windows Defender Information Disclosure Vulnerability

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.

9.3

CVSS3.1

CVE-2024-49147 - Microsoft Update Catalog Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

📅 Published: Dec. 12, 2024, 7:07 p.m. 🔄 Last Modified: May 13, 2025, 3:25 p.m.

5.4

CVSS3.1

CVE-2024-55876 - XWiki's scheduler in subwiki allows scheduling operations for any main wiki user

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Sche…

📅 Published: Dec. 12, 2024, 6:59 p.m. 🔄 Last Modified: April 30, 2025, 4:02 p.m.

9.8

CVSS3.1

CVE-2024-55875 - http4k has a potential XXE (XML External Entity Injection) vulnerability

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trig…

📅 Published: Dec. 12, 2024, 6:56 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2024-55663 - XWiki Platform has an SQL injection in getdocuments.vm with sort parameter

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on …

📅 Published: Dec. 12, 2024, 6:53 p.m. 🔄 Last Modified: Jan. 10, 2025, 6:02 p.m.

7.5

CVSS3.1

CVE-2024-47238 -

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

📅 Published: Dec. 12, 2024, 5:38 p.m. 🔄 Last Modified: Feb. 4, 2025, 3:52 p.m.

10

CVSS3.1

CVE-2024-55662 - XWiki allows remote code execution through the extension sheet

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed …

📅 Published: Dec. 12, 2024, 5:25 p.m. 🔄 Last Modified: April 30, 2025, 4:03 p.m.

6.5

CVSS3.1

CVE-2024-52901 - IBM InfoSphere Information Server denial of service

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

📅 Published: Dec. 12, 2024, 4:06 p.m. 🔄 Last Modified: Jan. 7, 2025, 6:16 p.m.
Total resulsts: 349182
Page 7497 of 34,919
« previous page » next page
Filters