6.9

CVSS4.0

CVE-2024-52524 - ReDoS in Giskard Scan text perturbation

Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponentialโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 5:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-37285 - Kibana arbitrary code execution via YAML deserialization

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.elastic.co/guide/en/eโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 4:49 p.m. ๐Ÿ”„ Last Modified: Oct. 1, 2025, 6:36 p.m.

7

CVSS4.0

CVE-2024-6068 - Input Validation Vulnerability exists in Arenaยฎ Input Analyzer

A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user must open a malicious DFT file.

๐Ÿ“… Published: Nov. 14, 2024, 4:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-10921 - Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the MongoDB Server. This issue affects MongoDB Server v5.0 versions prior to 5.0.30 , MongoDB Server v6.0 versions prior to 6.0โ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 4:04 p.m. ๐Ÿ”„ Last Modified: Oct. 1, 2025, 6:40 p.m.

5.1

CVSS4.0

CVE-2024-11214 - SourceCodester Best Employee Management System profile.php unrestricted upload

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely.โ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 4 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 3:38 p.m.

5.1

CVSS4.0

CVE-2024-11213 - SourceCodester Best Employee Management System edit_role.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit โ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 4 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 3:48 p.m.

3.7

CVSS3.1

CVE-2024-42188 - HCL Connections is vulnerable to a broken access control vulnerability

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

๐Ÿ“… Published: Nov. 14, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 6:45 p.m.

5.4

CVSS3.1

CVE-2024-52505 - matrix-appservice-irc allows IRC Command injection in provisioning API

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matriโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3:29 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-52302 - common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validaโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2024-11136 - Arbitrary file removal via path traversal in TCL Camera

The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from userโ€™s external storage.

๐Ÿ“… Published: Nov. 14, 2024, 3:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348389
Page 7797 of 34,839
ยซ previous page ยป next page
Filters