Latest CVE Feed
-
7.5
HIGHCVE-2024-40407
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
8.1
HIGHCVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-51027
Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 25, 2024
-
6.5
MEDIUMCVE-2024-50956
A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a craf... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 25, 2024
-
7.5
HIGHCVE-2024-50955
An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Mar. 13, 2025
-
8.8
HIGHCVE-2024-52554
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to ... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
8.8
HIGHCVE-2024-52553
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.... Read more
- Published: Nov. 13, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-52552
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
8.0
HIGHCVE-2024-52551
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous ... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
8.0
HIGHCVE-2024-52550
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build... Read more
Affected Products : pipeline\- Published: Nov. 13, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2024-52549
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission t... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2024-45879
The file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerab... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-45878
The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2024-45877
baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate informat... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 26, 2024
-
6.5
MEDIUMCVE-2024-45876
The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for manipulation of SQL queries.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-45875
The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 21, 2024
-
8.7
HIGHCVE-2024-41167
Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
- Published: Nov. 13, 2024
- Modified: Nov. 19, 2024
-
8.7
HIGHCVE-2024-40885
Use after free in the UEFI firmware of some Intel(R) Server M20NTP BIOS may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024
-
6.3
MEDIUMCVE-2024-39811
Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 15, 2024