Latest CVE Feed
-
8.6
HIGHCVE-2022-32144
There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability has been assigned a Common Vulnerabilities ... Read more
- Published: Dec. 20, 2024
- Modified: Jul. 11, 2025
-
3.3
LOWCVE-2020-9250
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the servic... Read more
- Published: Dec. 20, 2024
- Modified: Jul. 11, 2025
-
7.5
HIGHCVE-2024-54538
A denial-of-service issue was addressed with improved input validation. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, tvOS 18.1, macOS Sonoma 14.7.1, watchOS 11.1, macOS Ventura 13.7.1. A remote attacker may ... Read more
- Published: Dec. 20, 2024
- Modified: Jan. 06, 2025
-
8.3
HIGHCVE-2024-12832
Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authenticati... Read more
Affected Products : ng_firewall- Published: Dec. 20, 2024
- Modified: Jan. 03, 2025
-
7.8
HIGHCVE-2024-12831
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute... Read more
Affected Products : ng_firewall- Published: Dec. 20, 2024
- Modified: Jan. 03, 2025
-
8.1
HIGHCVE-2024-12830
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this... Read more
Affected Products : ng_firewall- Published: Dec. 20, 2024
- Modified: Jan. 03, 2025
-
8.8
HIGHCVE-2024-12829
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vuln... Read more
Affected Products : ng_firewall- Published: Dec. 20, 2024
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2024-56327
pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w. All details of GHSA-4fg7-vxc8-qx5w are relevant to `py... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 20, 2024
-
7.5
HIGHCVE-2024-54663
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files... Read more
Affected Products : zimbra_collaboration_suite- Published: Dec. 19, 2024
- Modified: Jun. 11, 2025
-
4.0
MEDIUMCVE-2024-54009
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
8.8
HIGHCVE-2024-12700
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-54984
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jan. 07, 2025
-
9.8
CRITICALCVE-2024-54983
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 31, 2024
-
0.0
NACVE-2024-54982
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the issue is in the chipset supply chain and is not localized to one or more Quectel produ... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jan. 16, 2025
-
4.7
MEDIUMCVE-2024-2201
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.... Read more
Affected Products : xen- Published: Dec. 19, 2024
- Modified: Jan. 09, 2025
-
8.8
HIGHCVE-2024-12729
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-12728
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-12727
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchang... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
8.5
HIGHCVE-2024-12672
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code... Read more
- Published: Dec. 19, 2024
- Modified: Apr. 03, 2025
-
8.5
HIGHCVE-2024-12175
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage ... Read more
Affected Products : arena- Published: Dec. 19, 2024
- Modified: Mar. 13, 2025