CVE-2024-21364 |
Description: Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
CVSS: CRITICAL (9.3) EPSS Score: 0.05%
January 1st, 2025 (4 months ago)
|
CVE-2024-21334 |
Description: Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVSS: CRITICAL (9.8) EPSS Score: 0.05%
January 1st, 2025 (4 months ago)
|
CVE-2024-21326 |
Description: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVSS: CRITICAL (9.6) EPSS Score: 0.05%
January 1st, 2025 (4 months ago)
|
CVE-2024-13061 |
Description: The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.
CVSS: CRITICAL (9.8) EPSS Score: 0.05%
January 1st, 2025 (4 months ago)
|
CVE-2024-12108 |
Description: In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
CVSS: CRITICAL (9.6) EPSS Score: 0.07%
January 1st, 2025 (4 months ago)
|
CVE-2024-12106 |
Description: In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
CVSS: CRITICAL (9.4) EPSS Score: 0.05%
January 1st, 2025 (4 months ago)
|
CVE-2024-0057 |
Description: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
CVSS: CRITICAL (9.1) EPSS Score: 0.15%
January 1st, 2025 (4 months ago)
|
CVE-2024-56799 |
Description: Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
CVSS: CRITICAL (10.0) EPSS Score: 0.04%
December 31st, 2024 (4 months ago)
|
CVE-2024-47926 |
Description: Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS: CRITICAL (9.8) EPSS Score: 0.04%
December 31st, 2024 (4 months ago)
|
CVE-2024-47919 |
Description: Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS: CRITICAL (9.8) EPSS Score: 0.04%
December 31st, 2024 (4 months ago)
|