7.7

CVSS4.0

CVE-2024-32759 - Johnson Controls Software House C●CURE 9000 installer password strength

Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

📅 Published: July 10, 2024, 5:43 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-6646 - Netgear WN604 Web Interface downloadFile.php information disclosure

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure…

📅 Published: July 10, 2024, 5:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2024-3325 - JasperReports Server Driver upload vulnerability

Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

📅 Published: July 10, 2024, 5:02 p.m. 🔄 Last Modified: Oct. 14, 2025, 4:38 p.m.

5.3

CVSS4.0

CVE-2024-6645 - WuKongOpenSource Wukong_nocode AviatorScript ExpressionUtil.java deserialization

A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ExpressionUtil.java of the component AviatorScript Handler. The manipulation leads to deserialization. The attack can …

📅 Published: July 10, 2024, 5 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-6644 - zmops ArgusDBM AviatorScript CalculateAlarm.java getDefaultClassLoader deserialization

A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java of the component AviatorScript Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely…

📅 Published: July 10, 2024, 4:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2024-5217 - Incomplete Input Validation in GlideExpression Script

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed …

📅 Published: July 10, 2024, 4:28 p.m. 🔄 Last Modified: Nov. 3, 2025, 6:58 p.m.

6.9

CVSS4.0

CVE-2024-5178 - Incomplete Input Validation in SecurelyAccess API

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is …

📅 Published: July 10, 2024, 4:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow UI Macros

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instan…

📅 Published: July 10, 2024, 4:16 p.m. 🔄 Last Modified: Nov. 3, 2025, 6:58 p.m.

6.7

CVSS3.1

CVE-2024-20456 -

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privilege…

📅 Published: July 10, 2024, 4:06 p.m. 🔄 Last Modified: Aug. 4, 2025, 5:44 p.m.

5.3

CVSS3.1

CVE-2023-33860 - IBM Security ReaQta information disclosure

IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the att…

📅 Published: July 10, 2024, 3:28 p.m. 🔄 Last Modified: May 19, 2025, 4:15 p.m.
Total resulsts: 348436
Page 9119 of 34,844
« previous page » next page
Filters