Latest CVE Feed
-
9.8
CRITICALCVE-2024-47540
GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the program calls gst... Read more
Affected Products : gstreamer- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-47539
GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memo... Read more
Affected Products : gstreamer- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-47538
GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64... Read more
Affected Products : gstreamer- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2024-47537
GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that s... Read more
Affected Products : gstreamer- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
8.1
HIGHCVE-2024-45404
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the t... Read more
Affected Products : opencti- Published: Dec. 12, 2024
- Modified: May. 17, 2025
-
9.1
CRITICALCVE-2024-45337
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this functio... Read more
Affected Products : ssh- Published: Dec. 12, 2024
- Modified: Feb. 18, 2025
-
7.8
HIGHCVE-2024-43600
Microsoft Office Elevation of Privilege Vulnerability... Read more
Affected Products : office- Published: Dec. 12, 2024
- Modified: Jan. 08, 2025
-
7.3
HIGH- Published: Dec. 12, 2024
- Modified: Jan. 08, 2025
-
9.9
CRITICALCVE-2024-42448
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.... Read more
Affected Products : veeam_service_provider_console- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
7.5
HIGHCVE-2024-37401
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.... Read more
- Published: Dec. 12, 2024
- Modified: Jul. 02, 2025
-
7.5
HIGHCVE-2024-37377
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.... Read more
- Published: Dec. 12, 2024
- Modified: Jul. 02, 2025
-
8.8
HIGHCVE-2024-12489
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/term.php. The manipulation of the argument id leads to sql injection. It is possibl... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
8.8
HIGHCVE-2024-12488
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/subject_update.php. The manipulation of the argument id leads to sql... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
8.8
HIGHCVE-2024-12487
A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/room_update.php. The manipulation of the argument id lead... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
8.8
HIGHCVE-2024-12486
A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It i... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
8.8
HIGHCVE-2024-12485
A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/department.php. The manipulation of the argument id leads to sql ... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2024-12484
A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated... Read more
Affected Products : technical_discussion_forum- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.3
MEDIUMCVE-2024-12483
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the atta... Read more
Affected Products : ujcms- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.3
MEDIUMCVE-2024-12482
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basic-common\src\main\java\tech\wetech\basic\util\BackupFileUtil.java of the com... Read more
Affected Products : wetech-cms- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
8.8
HIGHCVE-2024-12481
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\UserDao.java. The manipulation ... Read more
Affected Products : wetech-cms- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024