9.3

CVSS4.0

CVE-2024-6516 - Cross Site Scripting XSS

Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

📅 Published: Dec. 5, 2024, 12:24 p.m. 🔄 Last Modified: Dec. 5, 2024, 6:50 p.m.

8.7

CVSS4.0

CVE-2024-6515 - unauthorized file access

Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

📅 Published: Dec. 5, 2024, 12:22 p.m. 🔄 Last Modified: Dec. 5, 2024, 6:50 p.m.

4.3

CVSS4.0

CVE-2024-54127 - Exposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50

This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could a…

📅 Published: Dec. 5, 2024, 12:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-54126 - Insufficient Integrity Verification Vulnerability in TP-Link Archer C50

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious…

📅 Published: Dec. 5, 2024, 12:14 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2024-52270 - PDF Document Spoofing in DropBox Sign(HelloSign)

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability…

📅 Published: Dec. 5, 2024, 10:55 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2022-41137 - Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be…

📅 Published: Dec. 5, 2024, 10:01 a.m. 🔄 Last Modified: July 15, 2025, 4:34 p.m.

7.5

CVSS3.0

CVE-2024-52564 -

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configurat…

📅 Published: Dec. 5, 2024, 9:41 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.0

CVE-2024-47133 -

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

📅 Published: Dec. 5, 2024, 9:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-45841 -

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.

📅 Published: Dec. 5, 2024, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11324 - Accounting for WooCommerce <= 1.6.6 - Reflected Cross-Site Scripting

The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: Dec. 5, 2024, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347742
Page 7473 of 34,775
« previous page » next page
Filters