2051
|
9.8 |
CRITICAL
Network
beyondtrust
|
remote_support privileged_remote_access
|
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site u…
|
CWE-77
Command Injection
|
CVE-2024-12356
|
2024-12-21 00:25 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2052
|
9.8 |
CRITICAL
Network
cleo
|
lexicom vltrader harmony
|
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leve…
|
CWE-77
Command Injection
|
CVE-2024-55956
|
2024-12-21 00:21 |
2024-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2053
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
|
CWE-611
XXE
|
CVE-2024-56356
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2054
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
|
CWE-79
Cross-site Scripting
|
CVE-2024-56355
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2055
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-56354
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2056
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2024-56353
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2057
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
|
CWE-79
Cross-site Scripting
|
CVE-2024-56352
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2058
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-56351
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2059
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
|
CWE-863
Incorrect Authorization
|
CVE-2024-56350
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2060
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
|
CWE-862
Missing Authorization
|
CVE-2024-56349
|
2024-12-21 00:15 |
2024-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|