7.8

CVSS3.1

CVE-2024-10251 -

Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

๐Ÿ“… Published: Dec. 11, 2024, 4:40 p.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 4:55 a.m.

6.3

CVSS3.1

CVE-2024-28141 - Cross-Site Request-Forgery

The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the admโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 3:54 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS4.0

CVE-2024-47758 - GLPI vulnerable to account takeover without privilege escalation through the API

GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

๐Ÿ“… Published: Dec. 11, 2024, 3:50 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2025, 3:21 p.m.

6.1

CVSS3.1

CVE-2024-28140 - Violation of Least Privilege Principle

The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user.ย This can be confirmed by running "ps aux" as the root user and obserโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 3:48 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-28139 - Privilege escalation through sudo misconfiguration

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.

๐Ÿ“… Published: Dec. 11, 2024, 3:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.5

CVSS4.0

CVE-2024-53677 - Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload cheโ€ฆ

File upload logic in Apache Struts is flawed.ย An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4โ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 3:35 p.m. ๐Ÿ”„ Last Modified: July 15, 2025, 4:30 p.m.

4.7

CVSS3.1

CVE-2024-50585 - Reflected Cross-Site Scripting

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page.ย The vulnerability can be triggered by sending a speciallโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 2:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-12498 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Dec. 11, 2024, 1:02 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 11:15 p.m.

5.3

CVSS3.1

CVE-2024-11351 - Restrict โ€“ membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenโ€ฆ

The Restrict โ€“ membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extractโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 12:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-51460 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.

๐Ÿ“… Published: Dec. 11, 2024, 12:15 p.m. ๐Ÿ”„ Last Modified: Jan. 14, 2025, 7:40 p.m.
Total resulsts: 349182
Page 7524 of 34,919
ยซ previous page ยป next page
Filters