7.1

CVSS3.1

CVE-2024-10039 - keycloak-core: mTLS passthrough

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mecha…

📅 Published: Nov. 21, 2024, 4:45 p.m. 🔄 Last Modified: Nov. 21, 2024, 4:45 p.m.

5.5

CVSS3.1

CVE-2024-49529 - InDesign Desktop | Out-of-bounds Read (CWE-125)

InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a vi…

📅 Published: Nov. 21, 2024, 4:35 p.m. 🔄 Last Modified: Dec. 3, 2024, 2:37 p.m.

10

CVSS4.0

CVE-2024-8525 - Automated Logic WebCTRL and Carrier i-Vu Unrestricted File Upload

An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file.

📅 Published: Nov. 21, 2024, 3:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2024-8526 - Automated Logic WebCTRL and Carrier i-Vu Open Redirect

A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp"

📅 Published: Nov. 21, 2024, 3:29 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-28892 -

An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Dec. 20, 2024, 5:05 p.m.

9.8

CVSS3.1

CVE-2024-29224 -

An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Dec. 17, 2024, 10:20 p.m.

9.8

CVSS3.1

CVE-2024-21855 -

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Dec. 20, 2024, 5:05 p.m.

7.2

CVSS3.1

CVE-2024-28027 -

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities…

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

7.2

CVSS3.1

CVE-2024-28026 -

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities…

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

7.2

CVSS3.1

CVE-2024-28025 -

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities…

📅 Published: Nov. 21, 2024, 2:41 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.
Total resulsts: 346631
Page 7506 of 34,664
« previous page » next page
Filters