Currently trending CVE - Hype Score: 5 - go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.
Currently trending CVE - Hype Score: 4 - In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via ...
Attackers spent five months silently stealing emails from a stock exchange executive’s Outlook account in a suspected espionage operation. A threat actor quietly sat inside a senior executive’s Outlook account at a major global stock exchange for roughly 150 days, from October 2025 to March 2026. Broadcom’s Symantec and Carbon Black threat-hunting team investigated the […]
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token.
"Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said.
GitHub supports a feature called GitHub.dev that runs as
A vulnerability described as problematic has been identified in Rockwell Automation MicroLogix 1100. This issue affects some unknown processing of the component RUN Mode. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2021-33012. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in XPodas Octopod. It has been declared as very critical. This vulnerability affects unknown code. The manipulation results in authentication bypass by primary weakness. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is identified as CVE-2024-1202. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Mergen Software Quality Management System up to 25032024 and classified as critical. The impacted element is an unknown function. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2024-2865. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in Havelsan Dialogue 1.83.0. This affects an unknown function of the component ACL Handler. Performing a manipulation results in incorrect permission assignment.
This vulnerability is reported as CVE-2024-3375. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Vadi Corporate Information Systems DIGIKENT GIS up to 2.23.5. It has been rated as critical. Affected is an unknown function. Performing a manipulation results in sql injection.
This vulnerability is known as CVE-2024-1100. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in EMTA Grup PDKS up to 20240602. It has been declared as critical. This issue affects some unknown processing. Such manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2024-0336. The attack needs to be initiated within the local network. No exploit is available.
A vulnerability was found in TNB Mobile Solutions Cockpit Software up to 0.251.0. It has been classified as problematic. The impacted element is an unknown function. Performing a manipulation results in inclusion of sensitive information in source code.
This vulnerability was named CVE-2024-1272. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Next4Biz CRM & BPM Software Business Process Manangement 6.6.4.4. Affected by this issue is some unknown functionality. The manipulation leads to code injection.
This vulnerability is documented as CVE-2024-5683. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in Next4Biz CRM & BPM Software Business Process Manangement 6.6.4.4. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2024-4754. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Mia Technology Mia-Med Health Aplication up to 1.0.13. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes risky cryptographic algorithm.
This vulnerability appears as CVE-2024-3264. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Mia Technology Mia-Med Health Aplication up to 1.0.13. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is known as CVE-2024-5862. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.