8.8

CVSS3.1

CVE-2024-4252 - Tenda i22 formSetUrlFilterRule stack-based overflow

A vulnerability classified as critical has been found in Tenda i22 1.0.0.3(4687). This affects the function formSetUrlFilterRule. The manipulation of the argument groupIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulne…

📅 Published: April 27, 2024, 1:31 p.m. 🔄 Last Modified: Jan. 27, 2025, 6:27 p.m.

8.8

CVSS3.1

CVE-2024-4251 - Tenda i21 DhcpSetSe fromDhcpSetSer stack-based overflow

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been rated as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSe. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to stack-based buff…

📅 Published: April 27, 2024, 1 p.m. 🔄 Last Modified: Jan. 27, 2025, 6:22 p.m.

7.5

CVSS3.1

CVE-2024-25048 - IBM MQ code execution

IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.

📅 Published: April 27, 2024, 12:07 p.m. 🔄 Last Modified: July 3, 2025, 8:45 p.m.

8.8

CVSS3.1

CVE-2024-4250 - Tenda i21 wifiSSIDset formwrlSSIDset stack-based overflow

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be launched remotel…

📅 Published: April 27, 2024, noon 🔄 Last Modified: Jan. 27, 2025, 6:24 p.m.

8.8

CVSS3.1

CVE-2024-4249 - Tenda i21 wifiSSIDget formwrlSSIDget stack-based overflow

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The expl…

📅 Published: April 27, 2024, 11:31 a.m. 🔄 Last Modified: Jan. 27, 2025, 6:25 p.m.

8.8

CVSS3.1

CVE-2024-4248 - Tenda i21 formQosManage_user stack-based overflow

A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. This issue affects the function formQosManage_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The associated identifier of this vulnerabilit…

📅 Published: April 27, 2024, 10:31 a.m. 🔄 Last Modified: Jan. 27, 2025, 6:25 p.m.

6.4

CVSS3.1

CVE-2024-3309 - Qi Addons For Elementor <= 1.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Cou…

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's attributes in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri…

📅 Published: April 27, 2024, 9:37 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-4247 - Tenda i21 formQosManage_auto stack-based overflow

A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. This vulnerability affects the function formQosManage_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated remotely. VDB-262138 is the identifier assi…

📅 Published: April 27, 2024, 9:31 a.m. 🔄 Last Modified: Jan. 27, 2025, 6:27 p.m.

6.3

CVSS3.1

CVE-2023-1000 - cyanomiko dcnnt-py Notification notifications.py main command injection

A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to command injection. It is possible to launch the attack remotely.…

📅 Published: April 27, 2024, 9 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2024-3342 - Timetable and Event Schedule by MotoPress <= 2.4.11 - Authenticated (Contributor+) SQL Injection

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

📅 Published: April 27, 2024, 8:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10149 of 34,919
« previous page » next page
Filters