9.8

CVSS3.1

CVE-2024-12728 -

A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:20 p.m.

8.5

CVSS4.0

CVE-2024-11157 - Rockwell Automation Third Party Vulnerability in Arena

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimat…

📅 Published: Dec. 19, 2024, 8:48 p.m. 🔄 Last Modified: March 13, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-12727 -

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the f…

📅 Published: Dec. 19, 2024, 8:26 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:27 p.m.

8

CVSS3.1

CVE-2024-12111 - Potential LDAP injection vulnerability in OpenText Privileged Access Manager

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)

📅 Published: Dec. 19, 2024, 8:10 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:15 p.m.

6.5

CVSS3.1

CVE-2024-7139 - Denial of Service in Silicon Labs RS9116 Bluetooth SDK

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service.  If a watchdog timer is not enabled, a hard reset is required to recover the device.

📅 Published: Dec. 19, 2024, 7:24 p.m. 🔄 Last Modified: May 28, 2025, 2:15 p.m.

6.5

CVSS3.1

CVE-2024-7138 - Denial of Service in Silicon Labs RS9116 Bluetooth SDK

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required to recover the device.

📅 Published: Dec. 19, 2024, 7:23 p.m. 🔄 Last Modified: May 28, 2025, 2:15 p.m.

6.5

CVSS3.1

CVE-2024-7137 - Denial of Service in Silicon Labs RS9116 Bluetooth SDK

The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device.

📅 Published: Dec. 19, 2024, 7:23 p.m. 🔄 Last Modified: May 28, 2025, 2:15 p.m.

5.3

CVSS3.1

CVE-2024-49765 - Bypass of Discourse Connect using other login paths if enabled in Discourse

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgra…

📅 Published: Dec. 19, 2024, 7:15 p.m. 🔄 Last Modified: Sept. 26, 2025, 12:50 p.m.

2.2

CVSS3.1

CVE-2024-52589 - Moderators can view Screened emails even when the “moderators view emails” option is disabled in Di…

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove moderator role from un…

📅 Published: Dec. 19, 2024, 7:13 p.m. 🔄 Last Modified: Aug. 26, 2025, 2:16 a.m.

6.8

CVSS3.1

CVE-2024-52794 - Magnific lightbox susceptible to Cross-site Scripting in Discourse

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

📅 Published: Dec. 19, 2024, 7:12 p.m. 🔄 Last Modified: Aug. 26, 2025, 2:14 a.m.
Total resulsts: 344106
Page 6900 of 34,411
« previous page » next page
Filters