9.3

CVSS4.0

CVE-2024-12286 - MOBATIME Network Master Clock has a use of default credentials vulnerability

MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.

πŸ“… Published: Dec. 10, 2024, 5:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2024-53866 - pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasion

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data (including on first l…

πŸ“… Published: Dec. 10, 2024, 5:12 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:11 a.m.

7.6

CVSS3.1

CVE-2024-55602 - PenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d42…

πŸ“… Published: Dec. 10, 2024, 4:58 p.m. πŸ”„ Last Modified: April 18, 2025, 6:06 p.m.

0.0

CVE-2024-12424 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24592. Reason: This candidate is a reservation duplicate of CVE-2025-24592. Notes: All CVE users should reference CVE-2025-24592 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Dec. 10, 2024, 4:37 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 3:15 p.m.

0.0

CVSS3.1

CVE-2024-4109 - undertow: information leakage via HTTP/2 request header reuse

Red Hat Product Security has determined that this CVE is not a security vulnerability.

πŸ“… Published: Dec. 10, 2024, 4:35 p.m. πŸ”„ Last Modified: Jan. 16, 2025, 10:15 p.m.

6.9

CVSS4.0

CVE-2024-55548 - Denial of Service

Improper check of password character lenght in ORing IAP-420 allows a forced deadlock.Β This issue affects IAP-420: through 2.01e.

πŸ“… Published: Dec. 10, 2024, 4:34 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

9.3

CVSS4.0

CVE-2024-55547 - Remote Command Execution via SNMP

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection.Β This issue affects IAP-420: through 2.01e.

πŸ“… Published: Dec. 10, 2024, 4:27 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

7.1

CVSS4.0

CVE-2024-55546 - Stored Cross-Site Scripting

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

πŸ“… Published: Dec. 10, 2024, 4:21 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

7.1

CVSS4.0

CVE-2024-55545 - Reflected Cross-Site Scripting

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

πŸ“… Published: Dec. 10, 2024, 4:14 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

8.7

CVSS4.0

CVE-2024-55544 - Authenticated Command Injection

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

πŸ“… Published: Dec. 10, 2024, 4:04 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.
Total resulsts: 346569
Page 7291 of 34,657
Β« previous page Β» next page
Filters