9.4

CVSS3.1

CVE-2024-49806 - IBM Security Verify Access Appliance hard coded credentials

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

πŸ“… Published: Nov. 29, 2024, 4:53 p.m. πŸ”„ Last Modified: Jan. 29, 2025, 9:25 p.m.

9.4

CVSS3.1

CVE-2024-49805 - IBM Security Verify Access Appliance hard coded credentials

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

πŸ“… Published: Nov. 29, 2024, 4:52 p.m. πŸ”„ Last Modified: Jan. 29, 2025, 9:24 p.m.

9.8

CVSS3.1

CVE-2024-49803 - IBM Security Verify Access Appliance command execution

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

πŸ“… Published: Nov. 29, 2024, 4:50 p.m. πŸ”„ Last Modified: Jan. 29, 2025, 9:23 p.m.

9.1

CVSS3.1

CVE-2024-11992 - Path traversal vulnerability in Quick.CMS

Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in …

πŸ“… Published: Nov. 29, 2024, 1:06 p.m. πŸ”„ Last Modified: Nov. 29, 2024, 1:24 p.m.

4.6

CVSS3.1

CVE-2024-11990 - Cross-Site Scripting (XSS) en SurgeMail de NetWin

A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters.

πŸ“… Published: Nov. 29, 2024, 1 p.m. πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

5.7

CVSS4.0

CVE-2024-47094 - Logging of sitesecret to automations log

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

πŸ“… Published: Nov. 29, 2024, 9:52 a.m. πŸ”„ Last Modified: Sept. 11, 2025, 7:16 a.m.

9.8

CVSS3.0

CVE-2024-50357 -

FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authenticatio…

πŸ“… Published: Nov. 29, 2024, 9:06 a.m. πŸ”„ Last Modified: Dec. 2, 2024, 6:15 p.m.

4.3

CVSS3.1

CVE-2024-11014 -

Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.

πŸ“… Published: Nov. 29, 2024, 8:06 a.m. πŸ”„ Last Modified: July 24, 2025, 2:37 p.m.

7.2

CVSS3.1

CVE-2024-11013 -

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management in…

πŸ“… Published: Nov. 29, 2024, 8:03 a.m. πŸ”„ Last Modified: July 24, 2025, 2:40 p.m.

4.6

CVSS4.0

CVE-2024-9044 - XML External Entity (XXE) Vulnerability in EasyTax

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

πŸ“… Published: Nov. 29, 2024, 7:40 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 1:43 p.m.
Total resulsts: 343979
Page 7149 of 34,398
Β« previous page Β» next page
Filters