6.4

CVSS3.1

CVE-2024-48893 -

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 10:12 p.m.

3.5

CVSS3.1

CVE-2024-46665 -

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:09 p.m.

8.8

CVSS3.1

CVE-2024-11497 - Phoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalation

An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

πŸ“… Published: Jan. 14, 2025, 1:55 p.m. πŸ”„ Last Modified: Jan. 14, 2025, 2:17 p.m.

7.5

CVSS3.1

CVE-2024-11864 - SCP-Firmware Vulnerability

Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP

πŸ“… Published: Jan. 14, 2025, 1:46 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 4:42 p.m.

5.3

CVSS3.1

CVE-2024-11863 - SCP-Firmware Vulnerability

Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP

πŸ“… Published: Jan. 14, 2025, 1:45 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 4:42 p.m.

8.2

CVSS3.1

CVE-2024-7344 - Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned sof…

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

πŸ“… Published: Jan. 14, 2025, 1:29 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 3:36 p.m.

5.3

CVSS3.1

CVE-2024-7596 - Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network pack…

Proposed Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This…

πŸ“… Published: Jan. 14, 2025, noon πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

5.3

CVSS3.1

CVE-2024-7595 - GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet

GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered si…

πŸ“… Published: Jan. 14, 2025, noon πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

6.4

CVSS3.1

CVE-2024-12240 - Page Builder by SiteOrigin <= 2.31.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-…

πŸ“… Published: Jan. 14, 2025, 11:08 a.m. πŸ”„ Last Modified: April 8, 2026, 5:14 p.m.

9.1

CVSS4.0

CVE-2024-56841 -

A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.

πŸ“… Published: Jan. 14, 2025, 10:30 a.m. πŸ”„ Last Modified: Jan. 14, 2025, 2:32 p.m.
Total resulsts: 343919
Page 6625 of 34,392
Β« previous page Β» next page
Filters