CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-47585

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.

    Published: 10 Dec 2024
    5.3
    Medium

    CVE-2024-47582

    Last Modified: 15 Apr 2026

    Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

    Published: 10 Dec 2024
    4.3
    Medium

    CVE-2024-47581

    Last Modified: 15 Apr 2026

    SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-47580

    Last Modified: 15 Apr 2026

    An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-47579

    Last Modified: 15 Apr 2026

    An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

    Published: 10 Dec 2024
    9.1
    Critical

    CVE-2024-47578

    Last Modified: 15 Apr 2026

    Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

    Published: 10 Dec 2024
    2.7
    Low

    CVE-2024-47577

    Last Modified: 15 Apr 2026

    Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an attacker impersonating as authorized admin visits such server logs, then they get access to the customer data. The amount of leaked confidential data however is extremely limited, and the attacker has no control over what data is leaked.

    Published: 10 Dec 2024
    3.3
    Low

    CVE-2024-47576

    Last Modified: 15 Apr 2026

    SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.

    Published: 10 Dec 2024
    5.3
    Medium

    CVE-2024-32732

    Last Modified: 28 Oct 2025

    Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity and Availability of the application.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-54751

    Last Modified: 15 Apr 2026

    COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-45493

    Last Modified: 15 Apr 2026

    An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow them to authenticate with an internal user account from the network (if they know their password).

    Published: 10 Dec 2024
    7.4
    High

    CVE-2024-12397

    Last Modified: 15 Apr 2026

    A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-55586

    Last Modified: 15 Apr 2026

    Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.

    Published: 10 Dec 2024
    2.7
    Low

    CVE-2024-55550

    Last Modified: 4 Nov 2025

    Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-55500

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

    Published: 10 Dec 2024
    8
    High

    CVE-2024-46341

    Last Modified: 20 Jun 2025

    TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-50920

    Last Modified: 1 Jul 2025

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

    Published: 10 Dec 2024
    6.1
    Medium

    CVE-2024-53481

    Last Modified: 15 Apr 2025

    A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-45494

    Last Modified: 15 Apr 2026

    An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-46340

    Last Modified: 20 Jun 2025

    TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-46442

    Last Modified: 15 Apr 2026

    An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-46657

    Last Modified: 1 Jul 2025

    Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 10 Dec 2024
    8
    High

    CVE-2024-50699

    Last Modified: 2 Jul 2025

    TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

    Published: 10 Dec 2024
    6.5
    Medium

    CVE-2024-50921

    Last Modified: 1 Jul 2025

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.

    Published: 10 Dec 2024
    6.5
    Medium

    CVE-2024-50924

    Last Modified: 1 Jul 2025

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.

    Published: 10 Dec 2024
    6.5
    Medium

    CVE-2024-50928

    Last Modified: 1 Jul 2025

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.

    Published: 10 Dec 2024
    6.2
    Medium

    CVE-2024-50929

    Last Modified: 1 Jul 2025

    Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-50930

    Last Modified: 1 Jul 2025

    An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

    Published: 10 Dec 2024
    4.6
    Medium

    CVE-2024-50931

    Last Modified: 1 Jul 2025

    Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

    Published: 10 Dec 2024
    7.5
    High

    CVE-2024-51165

    Last Modified: 24 Jun 2025

    SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-53480

    Last Modified: 7 Apr 2025

    Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-53552

    Last Modified: 27 Jun 2025

    CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

    Published: 10 Dec 2024
    7.6
    High

    CVE-2024-53919

    Last Modified: 15 Apr 2026

    An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

    Published: 10 Dec 2024
    6.3
    Medium

    CVE-2024-9672

    Last Modified: 30 Jan 2025

    A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-55638

    Last Modified: 2 Jun 2025

    Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-55637

    Last Modified: 2 Jun 2025

    Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-55636

    Last Modified: 2 Jun 2025

    Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

    Published: 9 Dec 2024
    6.1
    Medium

    CVE-2024-55635

    Last Modified: 2 Jun 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

    Published: 9 Dec 2024
    8.1
    High

    CVE-2024-55634

    Last Modified: 2 Jun 2025

    A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

    Published: 9 Dec 2024
    2.7
    Low

    CVE-2024-12174

    Last Modified: 15 Apr 2026

    An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-55601

    Last Modified: 15 Apr 2026

    Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are Hugo users who do not trust their Markdown content files and are using one or more of these templates: `_default/_markup/render-link.html` from `v0.123.0`; `_default/_markup/render-image.html` from `v0.123.0`; `_default/_markup/render-table.html` from `v0.134.0`; and/or `shortcodes/youtube.html` from `v0.125.0`. This issue is patched in v0.139.4. As a workaround, one may replace an affected component with user defined templates or disable the internal templates.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-54151

    Last Modified: 18 Nov 2025

    Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` or `WEBSOCKETS_REST_AUTH` to "public", an unauthenticated user is able to do any of the supported operations (CRUD, subscriptions) with full admin privileges. This impacts any Directus instance that has either `WEBSOCKETS_GRAPHQL_AUTH` or `WEBSOCKETS_REST_AUTH` set to `public` allowing unauthenticated users to subscribe for changes on any collection or do REST CRUD operations on user defined collections ignoring permissions. Version 11.3.0 fixes the issue.

    Published: 9 Dec 2024
    8.4
    High

    CVE-2024-54149

    Last Modified: 24 Jun 2025

    Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandbox placed on Twig files and modify resources such as theme customisation values or modify, or remove, templates in the theme even if not provided direct access via the permissions. As all objects passed through to Twig are references to the live objects, it is also possible to also manipulate model data if models are passed directly to Twig, including changing attributes or even removing records entirely. In most cases, this is unwanted behavior and potentially dangerous. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any of the following permissions: `cms.manage_layouts`; `cms.manage_pages`; or `cms.manage_partials`. The Winter CMS maintainers strongly recommend that these permissions only be reserved to trusted administrators and developers in general. The maintainers of Winter CMS have significantly increased the scope of the sandbox, effectively making all models and datasources read-only in Twig, in versions 1.2.7, 1.1.11, and 1.0.476. Thse who cannot upgrade may apply commit fb88e6fabde3b3278ce1844e581c87dcf7daee22 to their Winter CMS installation manually to resolve the issue. In the rare event that a Winter user was relying on being able to write to models/datasources within their Twig templates, they should instead use or create components to make changes to their models.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-12393

    Last Modified: 2 Jun 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

    Published: 9 Dec 2024
    1.8
    Low

    CVE-2024-12057

    Last Modified: 15 Apr 2026

    User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.

    Published: 9 Dec 2024
    6.8
    Medium

    CVE-2024-54147

    Last Modified: 15 Apr 2026

    Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and response headers and bodies fully compromised including authorization tokens. The attack also allows obtaining full access to any signed-in Altair GraphQL Cloud account and replacing payment checkout pages with a malicious website. Version 8.0.5 fixes the issue.

    Published: 9 Dec 2024
    5.1
    Medium

    CVE-2024-53847

    Last Modified: 15 Apr 2026

    The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. Users should upgrade to Trix editor version 2.1.9 or 1.3.3, which uses DOMPurify to sanitize the pasted content.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-52599

    Last Modified: 22 Aug 2025

    Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in a tracker with a Gantt chart could force a victim to execute uncontrolled code. Tuleap Community Edition 16.1.99.50, Tuleap Enterprise Edition 16.1-4, and Tuleap Enterprise Edition 16.0-7 contain a fix.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-52586

    Last Modified: 15 Aug 2025

    eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker who can authenticate locally (by knowing or guessing the password of a user) can thus log in regardless of MFA requirements. This does not affect MFA that are performed by single sign-on services. Users are advised to upgrade to at least version 5.1.9 to receive a fix.

    Published: 9 Dec 2024
    7.8
    High

    CVE-2024-11608

    Last Modified: 26 Sept 2025

    A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 9 Dec 2024