8.5

CVSS4.0

CVE-2024-11156 - Rockwell Automation Arena® Out of Bounds Write Vulnerability

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit t…

📅 Published: Dec. 5, 2024, 5:37 p.m. 🔄 Last Modified: Dec. 17, 2024, 3:52 p.m.

8.5

CVSS4.0

CVE-2024-11155 - Rockwell Automation Arena® Use After Free Vulnerability

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To …

📅 Published: Dec. 5, 2024, 5:32 p.m. 🔄 Last Modified: April 14, 2025, 5:17 p.m.

5.3

CVSS4.0

CVE-2024-12235 - Shenzhen Dashi Tongzhou Information Technology AgileBPM AuthorizationTokenCheckFilter.java doFilter…

A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security-oauth2\src\main\java\com\dstz\auth\filter\A…

📅 Published: Dec. 5, 2024, 5:31 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:35 p.m.

5.5

CVSS3.1

CVE-2024-53846 - ssl fails to validate incorrect extened key usage

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27…

📅 Published: Dec. 5, 2024, 5:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-12234 - 1000 Projects Beauty Parlour Management System edit-customer-detailed.php sql injection

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-customer-detailed.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remot…

📅 Published: Dec. 5, 2024, 5 p.m. 🔄 Last Modified: Dec. 10, 2024, 11:25 p.m.

5.7

CVSS3.1

CVE-2024-54128 - Directus has an HTML Injection in Comment

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulner…

📅 Published: Dec. 5, 2024, 4:55 p.m. 🔄 Last Modified: Nov. 19, 2025, 2:47 p.m.

6.9

CVSS4.0

CVE-2024-12233 - code-projects Online Notice Board Profile Picture registration.php unrestricted upload

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may b…

📅 Published: Dec. 5, 2024, 4:31 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2024-12232 - code-projects Simple CRUD Functionality index.php cross site scripting

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The ex…

📅 Published: Dec. 5, 2024, 4 p.m. 🔄 Last Modified: Feb. 27, 2025, 8:54 p.m.

6.9

CVSS4.0

CVE-2024-12231 - CodeZips Project Management System index.php sql injection

A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed …

📅 Published: Dec. 5, 2024, 4 p.m. 🔄 Last Modified: Dec. 9, 2024, 6:59 p.m.

0.0

CVE-2024-51728 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024. Notes: none.

📅 Published: Dec. 5, 2024, 3:39 p.m. 🔄 Last Modified: Jan. 13, 2025, 10:15 a.m.
Total resulsts: 345156
Page 7209 of 34,516
« previous page » next page
Filters