6.5

CVSS3.1

CVE-2024-46430 -

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the setLoginPassword function, bypassi…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 6:12 p.m.

8

CVSS3.1

CVE-2024-46435 -

A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delF…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:38 p.m.

5.4

CVSS3.1

CVE-2024-48170 -

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Feb. 18, 2025, 8:15 p.m.

5.3

CVSS3.1

CVE-2024-12243 - Gnutls: gnutls impacted by inefficient der decoding in libtasn1 leading to remote dos

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially craft…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-46433 -

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 6:13 p.m.

8.8

CVSS3.1

CVE-2024-46429 -

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 6:21 p.m.

5.3

CVSS3.1

CVE-2024-12133 - Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, cau…

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-42513 -

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:21 p.m.

8.6

CVSS3.1

CVE-2024-42512 -

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: Sept. 29, 2025, 6:13 p.m.

8

CVSS3.1

CVE-2024-54954 -

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

πŸ“… Published: Feb. 10, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 4:49 p.m.
Total resulsts: 349182
Page 6810 of 34,919
Β« previous page Β» next page
Filters