Latest CVE Feed
-
6.3
MEDIUMCVE-2024-55514
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to u... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
9.1
CRITICALCVE-2024-55513
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading ... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
7.3
HIGHCVE-2024-49194
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could pote... Read more
Affected Products :- Published: Dec. 17, 2024
- Modified: Jul. 02, 2025
-
6.9
MEDIUMCVE-2024-56139
pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously crafted epub files can cause a stack overflow leading to a crash. This issue has not yet been addressed and users are advised to avoid u... Read more
Affected Products :- Published: Dec. 17, 2024
- Modified: Dec. 20, 2024
-
7.5
HIGHCVE-2024-51479
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly unde... Read more
Affected Products : next.js- Published: Dec. 17, 2024
- Modified: Sep. 10, 2025
-
9.1
CRITICALCVE-2024-55496
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.... Read more
Affected Products : bookstore_management_system- Published: Dec. 17, 2024
- Modified: May. 02, 2025
-
9.1
CRITICALCVE-2024-54662
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.... Read more
Affected Products :- Published: Dec. 17, 2024
- Modified: Dec. 18, 2024
-
3.7
LOWCVE-2024-49820
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability t... Read more
Affected Products : security_guardium_key_lifecycle_manager- Published: Dec. 17, 2024
- Modified: Jan. 10, 2025
-
7.5
HIGHCVE-2024-49819
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.... Read more
Affected Products : security_guardium_key_lifecycle_manager- Published: Dec. 17, 2024
- Modified: Jan. 10, 2025
-
4.3
MEDIUMCVE-2024-49818
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks ... Read more
Affected Products : security_guardium_key_lifecycle_manager- Published: Dec. 17, 2024
- Modified: Jan. 07, 2025
-
4.4
MEDIUMCVE-2024-49817
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.... Read more
Affected Products : security_guardium_key_lifecycle_manager- Published: Dec. 17, 2024
- Modified: Jan. 07, 2025
-
4.9
MEDIUMCVE-2024-49816
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.... Read more
Affected Products : security_guardium_key_lifecycle_manager- Published: Dec. 17, 2024
- Modified: Jan. 07, 2025
-
3.1
LOWCVE-2024-42194
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.... Read more
Affected Products :- Published: Dec. 17, 2024
- Modified: Dec. 17, 2024
-
0.0
NACVE-2024-53144
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for... Read more
Affected Products : linux_kernel- Published: Dec. 17, 2024
- Modified: Apr. 10, 2025
-
7.8
HIGHCVE-2024-12671
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context o... Read more
- Published: Dec. 17, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2024-12670
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the c... Read more
- Published: Dec. 17, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-12669
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the c... Read more
- Published: Dec. 17, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2024-12200
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context o... Read more
- Published: Dec. 17, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2024-12199
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context o... Read more
- Published: Dec. 17, 2024
- Modified: Aug. 26, 2025
-
7.8
HIGHCVE-2024-12198
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context o... Read more
- Published: Dec. 17, 2024
- Modified: May. 08, 2025