4.3

CVSS3.1

CVE-2024-20856 -

Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

๐Ÿ“… Published: May 7, 2024, 4:28 a.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 8:14 p.m.

4.4

CVSS3.1

CVE-2024-20821 -

A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode, which disables security features. This attack needs additional privilege to control TEE.

๐Ÿ“… Published: May 7, 2024, 4:25 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2023-42757 -

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-33149 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 5:16 p.m.

5.3

CVSS3.1

CVE-2024-33856 -

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 12:39 p.m.

9.4

CVSS3.1

CVE-2024-25514 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 7:02 p.m.

7.8

CVSS3.1

CVE-2024-25513 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 7:02 p.m.

6.5

CVSS3.1

CVE-2024-34517 -

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: July 23, 2025, 3:55 a.m.

5.3

CVSS3.1

CVE-2024-33858 -

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp directory.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 12:38 p.m.

6.5

CVSS3.1

CVE-2024-33783 -

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

๐Ÿ“… Published: May 7, 2024, midnight ๐Ÿ”„ Last Modified: June 16, 2025, 9:44 p.m.
Total resulsts: 349182
Page 9962 of 34,919
ยซ previous page ยป next page
Filters