7.8

CVSS3.1

CVE-2024-52945 -

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL coul…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:19 p.m.

5.3

CVSS3.1

CVE-2024-52921 -

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:17 p.m.

6.5

CVSS3.1

CVE-2024-52917 -

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:16 p.m.

5.4

CVSS3.1

CVE-2024-52944 -

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:19 p.m.

7.5

CVSS3.1

CVE-2023-49952 -

Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: May 7, 2025, 1:38 p.m.

7.5

CVSS3.1

CVE-2024-44757 -

An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:01 p.m.

9.8

CVSS3.1

CVE-2024-44756 -

NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:01 p.m.

6.1

CVSS3.1

CVE-2024-33231 -

Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-51053 -

An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-52926 -

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346102
Page 7534 of 34,611
Β« previous page Β» next page
Filters