9.8

CVSS3.1

CVE-2024-45494 -

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected fโ€ฆ

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2025, 5:31 p.m.

7.6

CVSS3.1

CVE-2024-53919 -

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 10, 2024, 4:15 p.m.

4.6

CVSS3.1

CVE-2024-50931 -

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 2:10 p.m.

8.8

CVSS3.1

CVE-2024-50930 -

An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 2:10 p.m.

9.8

CVSS3.1

CVE-2024-46340 -

TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:51 p.m.

8.8

CVSS3.1

CVE-2024-55500 -

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2024, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-54751 -

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2024, 4:15 p.m.

8

CVSS3.1

CVE-2024-50699 -

TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 2, 2025, 8:28 p.m.

6.5

CVSS3.1

CVE-2024-50928 -

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 3:32 p.m.

9.8

CVSS3.1

CVE-2024-46442 -

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

๐Ÿ“… Published: Dec. 10, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2024, 3:15 p.m.
Total resulsts: 343183
Page 6959 of 34,319
ยซ previous page ยป next page
Filters