CVE-2024-5743 – EveHome Eve Play Preimage Attack Giving RCE

The following table lists the changes that have been made to the CVE-2024-5743 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

CVE-2024-46479 – Venki Supravizio BPM Remote File Upload Vulnerability

The following table lists the changes that have been made to the CVE-2024-46479 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

Hackers exploit critical Aviatrix Controller RCE flaw in attacks

Hackers exploit critical Aviatrix Controller RCE flaw in attacks Threat actors are exploiting a critical remote command execution vulnerability, tracked as CVE-2024-50603, in Aviatrix Controller instances to install backdoors and crypto miners. The Aviatrix Control … Read more Published Date: Jan 13, 2025 (1 hour, 17 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-50603

CVE-2024-6352 – Ember ZNet Buffer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2024-6352 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

CVE-2024-57487 – “Code-Projects Online Car Rental File Upload Code Execution Vulnerability”

The following table lists the changes that have been made to the CVE-2024-57487 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

CVE-2024-57488 – Code-Projects Online Car Rental System Cross-Site Scripting (XSS)

The following table lists the changes that have been made to the CVE-2024-57488 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

CVE-2024-54999 – MonicaHQ Client-Side Injection Vulnerability

The following table lists the changes that have been made to the CVE-2024-54999 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

CVE-2024-48883 – Samsung Exynos Uplink Scheduling Message Information Leak

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The UE incorrectly handles a malformed uplink scheduling message, resulting in an information leak of the UE.

CVE-2024-12211 – Pega Platform Stored Cross-Site Scripting (XSS) Vulnerability

The following table lists the changes that have been made to the CVE-2024-12211 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 13, 2025 Action […]

UK domain registry Nominet confirms breach via Ivanti zero-day

UK domain registry Nominet confirms breach via Ivanti zero-day Nominet, the official .UK domain registry and one of the largest country code registries, has confirmed that its network was breached two weeks ago using an Ivanti VPN zero-day vulnerability. The comp … Read more Published Date: Jan 13, 2025 (2 hours, 24 minutes ago) Vulnerabilities has been […]