7.6

CVSS3.1

CVE-2024-53919 -

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-50931 -

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 2:10 p.m.

8.8

CVSS3.1

CVE-2024-50930 -

An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 2:10 p.m.

8.8

CVSS3.1

CVE-2024-55500 -

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-46340 -

TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:51 p.m.

7.4

CVSS3.1

CVE-2024-12397 - Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized โ€ฆ

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-55586 -

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-54751 -

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-50699 -

TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 2, 2025, 8:28 p.m.

6.5

CVSS3.1

CVE-2024-50928 -

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 3:32 p.m.
Total resulsts: 346554
Page 7296 of 34,656
ยซ previous page ยป next page
Filters