9.8

CVSS3.1

CVE-2024-45493 -

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate wโ€ฆ

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-55586 -

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2024-53919 -

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-55500 -

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-53552 -

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 5:58 p.m.

8.8

CVSS3.1

CVE-2024-50920 -

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 3:28 p.m.

7.5

CVSS3.1

CVE-2024-51165 -

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:37 a.m.

9.8

CVSS3.1

CVE-2024-45494 -

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected fโ€ฆ

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-50931 -

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 2:10 p.m.

7.4

CVSS3.1

CVE-2024-12397 - Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized โ€ฆ

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7559 of 34,919
ยซ previous page ยป next page
Filters