Latest CVE Feed
-
7.5
HIGHCVE-2024-53523
JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
8.4
HIGHCVE-2024-53589
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2024-53442
whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2024-41579
DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
8.7
HIGHCVE-2024-11148
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
5.0
MEDIUMCVE-2024-10933
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
9.1
CRITICAL- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2023-48010
STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access t... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
6.5
MEDIUMCVE-2024-12235
A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
8.5
HIGHCVE-2024-12130
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor c... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 17, 2024
-
8.5
HIGHCVE-2024-11158
An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor... Read more
- Published: Dec. 05, 2024
- Modified: Apr. 18, 2025
-
8.5
HIGHCVE-2024-11156
An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerabi... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 17, 2024
-
8.5
HIGHCVE-2024-11155
A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this ... Read more
- Published: Dec. 05, 2024
- Modified: Apr. 14, 2025
-
5.7
MEDIUMCVE-2024-54128
Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which ca... Read more
Affected Products : directus- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
5.5
MEDIUMCVE-2024-53846
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP st... Read more
Affected Products : otp- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
7.5
HIGHCVE-2024-53490
Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2024-12234
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-customer-detailed.php. The manipulation of the argument name leads to sql injectio... Read more
Affected Products : beauty_parlour_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2024-12233
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img le... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.2
CRITICALCVE-2024-54130
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when a bundle with a Destination Endpoint ID (EID) set to dtn:none is ... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
9.2
CRITICALCVE-2024-54129
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the i... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024