Total
2927 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-26201 | 1 Microsoft | 1 Intune Company Portal | 2024-12-31 | 6.6 Medium |
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | ||||
CVE-2024-29060 | 1 Microsoft | 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 | 2024-12-31 | 6.7 Medium |
Visual Studio Elevation of Privilege Vulnerability | ||||
CVE-2024-29054 | 1 Microsoft | 1 Defender For Iot | 2024-12-31 | 7.2 High |
Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||||
CVE-2024-29055 | 1 Microsoft | 1 Defender For Iot | 2024-12-31 | 7.2 High |
Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||||
CVE-2024-21376 | 1 Microsoft | 1 Azure Kubernetes Service | 2024-12-31 | 9 Critical |
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | ||||
CVE-2024-21364 | 1 Microsoft | 1 Azure Site Recovery | 2024-12-31 | 9.3 Critical |
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | ||||
CVE-2024-20695 | 1 Microsoft | 1 Skype For Business Server | 2024-12-31 | 5.7 Medium |
Skype for Business Information Disclosure Vulnerability | ||||
CVE-2024-21401 | 1 Microsoft | 1 Entra Jira Sso Plugin | 2024-12-31 | 9.8 Critical |
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | ||||
CVE-2024-20675 | 1 Microsoft | 1 Edge Chromium | 2024-12-31 | 6.3 Medium |
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||||
CVE-2024-20657 | 1 Microsoft | 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more | 2024-12-31 | 7 High |
Windows Group Policy Elevation of Privilege Vulnerability | ||||
CVE-2024-13067 | 2024-12-31 | 5.3 Medium | ||
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-25133 | 2024-12-31 | 8.8 High | ||
A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod. | ||||
CVE-2024-13022 | 2024-12-30 | 6.3 Medium | ||
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Management. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-13030 | 2024-12-30 | 7.3 High | ||
A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-12984 | 2024-12-27 | 5.3 Medium | ||
A vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B, IPC-IP3M-943S, IPC-IP3M-HX2B and IPC-IPM-721S up to 20241211. This affects an unknown part of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2024-0104 | 1 Nvidia | 8 Mga100-hs2, Mlnx-gw, Mlnx-os and 5 more | 2024-12-26 | 4.2 Medium |
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges. | ||||
CVE-2024-12956 | 2024-12-26 | 6.3 Medium | ||
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file /add_achievement_details.php. The manipulation of the argument ach_certy leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-12954 | 2024-12-26 | 6.3 Medium | ||
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file /update_ach.php. The manipulation of the argument ach_certy leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-12953 | 2024-12-26 | 6.3 Medium | ||
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown functionality of the file /update_pd_process.php. The manipulation of the argument profile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-12951 | 2024-12-26 | 6.3 Medium | ||
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /add_personal_details.php. The manipulation of the argument profile leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |