CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2024-52271

    Last Modified: 15 Apr 2026

    User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects Documenso: through 1.8.0, >1.8.0 and Documenso SaaS (Hosted) as of 2024-12-05.

    Published: 5 Dec 2024
    5.3
    Medium

    CVE-2024-53702

    Last Modified: 4 Nov 2025

    Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

    Published: 5 Dec 2024
    6.3
    Medium

    CVE-2024-45319

    Last Modified: 4 Nov 2025

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent the certificate requirement during authentication.

    Published: 5 Dec 2024
    8.5
    High

    CVE-2024-12130

    Last Modified: 17 Dec 2024

    An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

    Published: 5 Dec 2024
    8.1
    High

    CVE-2024-45318

    Last Modified: 4 Nov 2025

    A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

    Published: 5 Dec 2024
    8.5
    High

    CVE-2024-11158

    Last Modified: 18 Apr 2025

    An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-40763

    Last Modified: 6 Nov 2025

    Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.

    Published: 5 Dec 2024
    8.5
    High

    CVE-2024-11156

    Last Modified: 17 Dec 2024

    An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

    Published: 5 Dec 2024
    8.5
    High

    CVE-2024-11155

    Last Modified: 14 Apr 2025

    A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

    Published: 5 Dec 2024
    6.8
    Medium

    CVE-2024-12227

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. Upgrading to version 2.0.148.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 5 Dec 2024
    6.9
    Medium

    CVE-2024-12234

    Last Modified: 10 Dec 2024

    A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-customer-detailed.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-51555

    Last Modified: 15 Apr 2026

    Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-51554

    Last Modified: 5 Dec 2024

    Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-51551

    Last Modified: 5 Dec 2024

    Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-51550

    Last Modified: 5 Dec 2024

    Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-51549

    Last Modified: 5 Dec 2024

    Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.7
    High

    CVE-2024-51548

    Last Modified: 5 Dec 2024

    Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.7
    High

    CVE-2024-51546

    Last Modified: 10 Apr 2025

    Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-51545

    Last Modified: 5 Dec 2024

    Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-51544

    Last Modified: 10 Apr 2025

    Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-51543

    Last Modified: 5 Dec 2024

    Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-51542

    Last Modified: 10 Apr 2025

    Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-51541

    Last Modified: 5 Dec 2024

    Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-48847

    Last Modified: 5 Dec 2024

    MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

    Published: 5 Dec 2024
    7.1
    High

    CVE-2024-48846

    Last Modified: 5 Dec 2024

    Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-48845

    Last Modified: 5 Dec 2024

    Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

    Published: 5 Dec 2024
    7.2
    High

    CVE-2024-48844

    Last Modified: 5 Dec 2024

    Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    7.6
    High

    CVE-2024-48843

    Last Modified: 5 Dec 2024

    Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-48840

    Last Modified: 5 Dec 2024

    Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-48839

    Last Modified: 5 Dec 2024

    Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    5.4
    Medium

    CVE-2024-12094

    Last Modified: 15 Apr 2026

    This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. Note: To exploit this vulnerability, the device must be rooted/jailbroken.

    Published: 5 Dec 2024
    8.7
    High

    CVE-2024-6784

    Last Modified: 10 Apr 2025

    Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-6516

    Last Modified: 5 Dec 2024

    Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.7
    High

    CVE-2024-6515

    Last Modified: 5 Dec 2024

    Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    4.3
    Medium

    CVE-2024-54127

    Last Modified: 15 Apr 2026

    This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to obtain Wi-Fi credentials of the targeted system.

    Published: 5 Dec 2024
    8.5
    High

    CVE-2024-54126

    Last Modified: 15 Apr 2026

    This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

    Published: 5 Dec 2024
    5.3
    Medium

    CVE-2024-12232

    Last Modified: 27 Feb 2025

    A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Dec 2024
    6.9
    Medium

    CVE-2024-12231

    Last Modified: 9 Dec 2024

    A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Dec 2024
    5.9
    Medium

    CVE-2024-10716

    Last Modified: 13 Jul 2025

    Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

    Published: 5 Dec 2024
    —
    Unknown

    CVE-2024-12246

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Dec 2024
    8.2
    High

    CVE-2024-52270

    Last Modified: 15 Apr 2026

    User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened. This issue affects DropBox Sign(HelloSign): through 2024-12-04.

    Published: 5 Dec 2024
    5.9
    Medium

    CVE-2024-11942

    Last Modified: 2 Jun 2025

    A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-11941

    Last Modified: 2 Jun 2025

    A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

    Published: 5 Dec 2024
    6.9
    Medium

    CVE-2024-12230

    Last Modified: 10 Dec 2024

    A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/subcategory.php. The manipulation of the argument category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Dec 2024
    6.9
    Medium

    CVE-2024-12229

    Last Modified: 10 Dec 2024

    A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument search leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Dec 2024
    —
    Unknown

    CVE-2024-12242

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Dec 2024
    8.3
    High

    CVE-2022-41137

    Last Modified: 15 Jul 2025

    Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-52564

    Last Modified: 15 Apr 2026

    Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered.

    Published: 5 Dec 2024
    7.2
    High

    CVE-2024-47133

    Last Modified: 15 Apr 2026

    UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

    Published: 5 Dec 2024
    6.5
    Medium

    CVE-2024-45841

    Last Modified: 15 Apr 2026

    Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.

    Published: 5 Dec 2024