9.3
CVE-2024-12286 - MOBATIME Network Master Clock has a use of default credentials vulnerability
MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
5.8
CVE-2024-53866 - pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasion
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data (including on first lβ¦
7.6
CVE-2024-55602 - PenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit 1d42β¦
0.0
CVE-2024-12424 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24592. Reason: This candidate is a reservation duplicate of CVE-2025-24592. Notes: All CVE users should reference CVE-2025-24592 instead of this candidate. All references and descriptions in this candidate have been removed to prevβ¦
0.0
CVE-2024-4109 - undertow: information leakage via HTTP/2 request header reuse
Red Hat Product Security has determined that this CVE is not a security vulnerability.
6.9
CVE-2024-55548 - Denial of Service
Improper check of password character lenght in ORing IAP-420 allows a forced deadlock.Β This issue affects IAP-420: through 2.01e.
9.3
CVE-2024-55547 - Remote Command Execution via SNMP
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection.Β This issue affects IAP-420: through 2.01e.
7.1
CVE-2024-55546 - Stored Cross-Site Scripting
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
7.1
CVE-2024-55545 - Reflected Cross-Site Scripting
Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
8.7
CVE-2024-55544 - Authenticated Command Injection
Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.