Latest CVE Feed
-
8.8
HIGHCVE-2024-12700
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-54984
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jan. 07, 2025
-
9.8
CRITICALCVE-2024-54983
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 31, 2024
-
0.0
NACVE-2024-54982
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the issue is in the chipset supply chain and is not localized to one or more Quectel produ... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jan. 16, 2025
-
4.7
MEDIUMCVE-2024-2201
A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.... Read more
Affected Products : xen- Published: Dec. 19, 2024
- Modified: Jan. 09, 2025
-
8.8
HIGHCVE-2024-12729
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-12728
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-12727
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchang... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
8.5
HIGHCVE-2024-12672
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code... Read more
- Published: Dec. 19, 2024
- Modified: Apr. 03, 2025
-
8.5
HIGHCVE-2024-12175
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage ... Read more
Affected Products : arena- Published: Dec. 19, 2024
- Modified: Mar. 13, 2025
-
8.5
HIGHCVE-2024-11364
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat ac... Read more
- Published: Dec. 19, 2024
- Modified: Jul. 11, 2025
-
8.5
HIGHCVE-2024-11157
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code... Read more
Affected Products : arena- Published: Dec. 19, 2024
- Modified: Mar. 13, 2025
-
6.5
MEDIUMCVE-2024-7139
Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service. If a watchdog timer is not enabled, a hard reset is required to rec... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: May. 28, 2025
-
6.5
MEDIUMCVE-2024-7138
An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required to recover the device.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: May. 28, 2025
-
6.5
MEDIUMCVE-2024-7137
The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed d... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-53991
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the D... Read more
Affected Products : discourse- Published: Dec. 19, 2024
- Modified: Aug. 26, 2025
-
6.8
MEDIUMCVE-2024-52794
Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this v... Read more
Affected Products : discourse- Published: Dec. 19, 2024
- Modified: Aug. 26, 2025
-
2.7
LOWCVE-2024-52589
Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to ... Read more
Affected Products : discourse- Published: Dec. 19, 2024
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2024-49765
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest... Read more
Affected Products : discourse- Published: Dec. 19, 2024
- Modified: Aug. 26, 2025
-
8.0
HIGHCVE-2024-12111
In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024