2.1

CVSS4.0

CVE-2024-56324 - GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability can result in additiโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 3:56 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 7:22 p.m.

2.1

CVSS4.0

CVE-2024-56322 - GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when GoCD periodically scanโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 3:49 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 7:24 p.m.

3.8

CVSS3.1

CVE-2024-56321 - GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access

GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's user, rather than pre-configured scripts. Iโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 3:41 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 8:03 p.m.

9.4

CVSS4.0

CVE-2024-56320 - GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authenticated GoCD user with an existing GoCD useโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 3:37 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 8:09 p.m.

4.2

CVSS3.1

CVE-2024-41780 - IBM Jazz Foundation information disclosure

IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.

๐Ÿ“… Published: Jan. 3, 2025, 2:38 p.m. ๐Ÿ”„ Last Modified: March 21, 2025, 3:34 p.m.

4.3

CVSS3.1

CVE-2024-5591 - IBM Jazz Foundation information disclosure

IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

๐Ÿ“… Published: Jan. 3, 2025, 2:33 p.m. ๐Ÿ”„ Last Modified: March 21, 2025, 3:35 p.m.

9.3

CVSS4.0

CVE-2024-9140 -

Moxaโ€™s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant โ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 8:26 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12132 - WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticโ€ฆ

The WP Job Portal โ€“ A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:25 p.m.

8.6

CVSS4.0

CVE-2024-9138 - Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliances

Moxaโ€™s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a signifiโ€ฆ

๐Ÿ“… Published: Jan. 3, 2025, 8:14 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-53842 -

In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Jan. 3, 2025, 3:28 a.m. ๐Ÿ”„ Last Modified: July 24, 2025, 3:13 p.m.
Total resulsts: 345141
Page 6886 of 34,515
ยซ previous page ยป next page
Filters