7.8

CVSS3.1

CVE-2024-52945 -

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL coul…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:19 p.m.

5.3

CVSS3.1

CVE-2024-52921 -

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:17 p.m.

6.5

CVSS3.1

CVE-2024-52917 -

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:16 p.m.

5.4

CVSS3.1

CVE-2024-52944 -

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:19 p.m.

7.5

CVSS3.1

CVE-2024-52940 -

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Nov. 23, 2024, 4:55 a.m.

9.8

CVSS3.1

CVE-2015-20111 -

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunc…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Nov. 18, 2024, 5:35 p.m.

7.5

CVSS3.1

CVE-2023-49952 -

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: May 7, 2025, 1:38 p.m.

9.8

CVSS3.1

CVE-2024-51051 -

AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Nov. 19, 2024, 9:57 p.m.

7.5

CVSS3.1

CVE-2024-44757 -

An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:01 p.m.

8.8

CVSS3.1

CVE-2024-48292 -

An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Nov. 19, 2024, 9:57 p.m.
Total resulsts: 343996
Page 7323 of 34,400
Β« previous page Β» next page
Filters