0.0

CVE-2024-12904 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Dec. 23, 2024, 12:30 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

8.4

CVSS3.1

CVE-2024-12902 - Global Wisdom Software ANCHOR - Undocumented Privileged Account

ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these accounts use default passwords, attackers could remotely log in to the virtual machine using the default cred…

πŸ“… Published: Dec. 23, 2024, 10:16 a.m. πŸ”„ Last Modified: Dec. 24, 2024, 2:01 a.m.

6.4

CVSS3.1

CVE-2024-11230 - Elementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Script…

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu…

πŸ“… Published: Dec. 23, 2024, 4:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2024-12901 - FoxCMS API Endpoint Site.php improper authorization

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The attack can be launc…

πŸ“… Published: Dec. 23, 2024, 2 a.m. πŸ”„ Last Modified: July 15, 2025, 8:15 p.m.

5.3

CVSS4.0

CVE-2024-12900 - FoxCMS Configuration File installdb.php code injection

A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack …

πŸ“… Published: Dec. 23, 2024, 1:31 a.m. πŸ”„ Last Modified: July 15, 2025, 8:08 p.m.

6.9

CVSS4.0

CVE-2024-12899 - 1000 Projects Attendance Tracking Management System course_action.php sql injection

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql injection. The attack may be initiated remo…

πŸ“… Published: Dec. 23, 2024, 12:31 a.m. πŸ”„ Last Modified: Jan. 8, 2025, 6:47 p.m.

7.2

CVSS3.0

CVE-2024-54082 -

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user.

πŸ“… Published: Dec. 23, 2024, 12:18 a.m. πŸ”„ Last Modified: Dec. 24, 2024, 12:39 a.m.

5.9

CVSS3.0

CVE-2024-52321 -

Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a remote unauthenticated attacker.

πŸ“… Published: Dec. 23, 2024, 12:18 a.m. πŸ”„ Last Modified: Dec. 24, 2024, 12:39 a.m.

5.3

CVSS3.0

CVE-2024-47864 -

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may get the web console of the product down.

πŸ“… Published: Dec. 23, 2024, 12:18 a.m. πŸ”„ Last Modified: Dec. 24, 2024, 12:39 a.m.

9.8

CVSS3.0

CVE-2024-46873 -

Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker.

πŸ“… Published: Dec. 23, 2024, 12:17 a.m. πŸ”„ Last Modified: Dec. 24, 2024, 12:39 a.m.
Total resulsts: 343921
Page 6866 of 34,393
Β« previous page Β» next page
Filters