9.8

CVSS3.1

CVE-2024-52765 -

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 2:15 p.m.

9.1

CVSS3.1

CVE-2024-29292 -

Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-51162 -

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes…

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2024-11483 - Automation-gateway: aap-gateway: improper scope handling in oauth2 tokens for aap 2.5

A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. While …

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-48982 -

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case. Supplying a length less than…

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2024, 9:15 p.m.

8

CVSS3.1

CVE-2024-52739 -

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: May 9, 2025, 2:09 p.m.

3.5

CVSS3.1

CVE-2024-52754 -

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, 5:15 p.m.

8

CVSS3.1

CVE-2024-51151 -

D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-51209 -

Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 7:32 p.m.

0.0

CVE-2024-49203 -

Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product is not intended to defend against a developer who uses untrusted input directly in query construction.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344690
Page 7335 of 34,469
Β« previous page Β» next page
Filters