Latest CVE Feed
-
9.8
CRITICALCVE-2024-55586
Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 12, 2024
-
7.8
HIGHCVE-2024-54095
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 10). The affected application is vulnerable to integer underflow vulnerability which can be triggered while parsing specially crafted PAR files. This could allow an att... Read more
Affected Products : solid_edge_se2024- Published: Dec. 10, 2024
- Modified: Mar. 04, 2025
-
7.8
HIGHCVE-2024-54094
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the ... Read more
Affected Products : solid_edge_se2024- Published: Dec. 10, 2024
- Modified: Mar. 04, 2025
-
7.8
HIGHCVE-2024-54093
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted ASM files. This could allow an attacker to execute code in the ... Read more
Affected Products : solid_edge_se2024- Published: Dec. 10, 2024
- Modified: Mar. 04, 2025
-
7.8
HIGHCVE-2024-54091
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T ... Read more
Affected Products : solid_edge_se2024- Published: Dec. 10, 2024
- Modified: Apr. 08, 2025
-
5.9
MEDIUMCVE-2024-54005
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
5.1
MEDIUMCVE-2024-53832
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the S... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
7.8
HIGHCVE-2024-53242
A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions < V2312.0008), Tecnomatix Plant Simulation V2302 (A... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
7.8
HIGHCVE-2024-53041
A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions < V2312.0008), Tecnomatix Plant Simulation V2302 (A... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
7.3
HIGHCVE-2024-52051
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),... Read more
Affected Products : simatic_wincc- Published: Dec. 10, 2024
- Modified: Aug. 12, 2025
-
8.4
HIGHCVE-2024-49849
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7... Read more
Affected Products : simatic_wincc- Published: Dec. 10, 2024
- Modified: Aug. 12, 2025
-
5.7
MEDIUMCVE-2024-49704
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2024-47117
IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea... Read more
Affected Products : carbon_charts- Published: Dec. 10, 2024
- Modified: Aug. 15, 2025
-
8.8
HIGHCVE-2020-28398
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All ... Read more
Affected Products : ruggedcom_rox_mx5000_firmware ruggedcom_rox_rx1400_firmware ruggedcom_rox_rx1500_firmware ruggedcom_rox_rx1501_firmware ruggedcom_rox_rx1510_firmware ruggedcom_rox_rx1511_firmware ruggedcom_rox_rx1512_firmware ruggedcom_rox_rx1524_firmware ruggedcom_rox_rx1536_firmware ruggedcom_rox_rx5000_firmware +1 more products- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
5.3
MEDIUMCVE-2024-11868
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to ext... Read more
Affected Products : learnpress- Published: Dec. 10, 2024
- Modified: Jan. 14, 2025
-
8.8
HIGHCVE-2024-52538
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote a... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 04, 2025
-
8.8
HIGHCVE-2024-47977
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote a... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2024-47484
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 04, 2025
-
6.4
MEDIUMCVE-2024-11928
The iChart – Easy Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible ... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
5.3
MEDIUMCVE-2024-11106
The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from... Read more
Affected Products : simple_restrict- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024