3.1

CVSS3.0

CVE-2024-53701 -

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security…

πŸ“… Published: Nov. 29, 2024, 5:39 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-11979 - Interinfo DreamMaker - Unrestricted File Upload through Path Traversal

DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

πŸ“… Published: Nov. 29, 2024, 2:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-11978 - Interinfo DreamMaker - Arbitrary File Reading through Path Traversal

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

πŸ“… Published: Nov. 29, 2024, 2:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-52778 -

DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.php.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:08 p.m.

7.5

CVSS3.1

CVE-2024-48651 -

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-39162 -

pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-36624 -

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:49 p.m.

5.5

CVSS3.1

CVE-2024-35369 -

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in unde…

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 4:06 p.m.

9.1

CVSS3.1

CVE-2024-35367 -

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

6.1

CVSS3.1

CVE-2024-36625 -

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:50 p.m.
Total resulsts: 349182
Page 7671 of 34,919
Β« previous page Β» next page
Filters