Latest CVE Feed
-
5.9
MEDIUMCVE-2024-53284
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges ... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53283
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges t... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53282
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileg... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53281
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files contain... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53280
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator priv... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53279
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read ... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.7
MEDIUMCVE-2024-55582
Oxide before 6 has unencrypted Control Plane datastores.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
7.5
HIGHCVE-2024-55580
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality ri... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
8.8
HIGHCVE-2024-55579
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2024-55578
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.... Read more
Affected Products : zammad- Published: Dec. 09, 2024
- Modified: Apr. 15, 2025
-
6.6
MEDIUMCVE-2024-55566
ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 17, 2024
-
4.3
MEDIUMCVE-2024-55565
nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.... Read more
Affected Products : nanoid- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2024-55564
The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
7.8
HIGHCVE-2024-12355
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input valid... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
7.8
HIGHCVE-2024-12354
A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
7.8
HIGHCVE-2024-12353
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name lead... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2024-12352
A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
5.3
MEDIUMCVE-2024-55563
Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents p... Read more
Affected Products : bitcoin_core- Published: Dec. 09, 2024
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2024-12351
A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
8.8
HIGHCVE-2024-12350
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The manipulation of the... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024