4.6

CVSS3.1

CVE-2022-33954 - IBM Robotic Process Automation information disclosure

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.

πŸ“… Published: Dec. 19, 2024, 12:44 a.m. πŸ”„ Last Modified: March 27, 2025, 3:59 p.m.

5.9

CVSS3.1

CVE-2021-39081 - IBM Cognos Analytics Mobile information disclosure

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

πŸ“… Published: Dec. 19, 2024, 12:22 a.m. πŸ”„ Last Modified: July 29, 2025, 11:42 p.m.

7.5

CVSS3.1

CVE-2024-55082 -

A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive information via a crafted request.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Jan. 2, 2025, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-54983 -

An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Dec. 31, 2024, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-55081 -

An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Jan. 2, 2025, 8:16 p.m.

0.0

CVE-2024-54982 -

An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the issue is in the chipset supply chain and is not localized to one or more Quectel products.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Jan. 16, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-55196 -

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Jan. 2, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2024-54790 -

A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 4:30 p.m.

7.5

CVSS3.1

CVE-2024-54663 -

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot directory. Exploitation requ…

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 9:17 p.m.

9.8

CVSS3.1

CVE-2024-54984 -

An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.

πŸ“… Published: Dec. 19, 2024, midnight πŸ”„ Last Modified: Jan. 9, 2025, 4:28 p.m.
Total resulsts: 344062
Page 6903 of 34,407
Β« previous page Β» next page
Filters