5.3

CVSS4.0

CVE-2024-12990 - ruifang-tech Rebuild Admin Verification Page admin-verify redirect

A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the component Admin Verification Page. The manipulation of the argument nexturl with the input http://localhost/evil.html leads to open redi…

πŸ“… Published: Dec. 27, 2024, 6 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-12989 - WISI Tangram GT31 HTTP Request server-side request forgery

A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely. The vendor was contact…

πŸ“… Published: Dec. 27, 2024, 5:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-12988 - Netgear R6900P/R7000P HTTP Header sub_16C4C buffer overflow

A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to buffer overflow. The attack can be launched remotely. The e…

πŸ“… Published: Dec. 27, 2024, 5 p.m. πŸ”„ Last Modified: May 28, 2025, 8:19 p.m.

7.2

CVSS3.1

CVE-2024-12856 - Four-Faith Industrial Router adjust_sys_time OS Command Injection

The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this …

πŸ“… Published: Dec. 27, 2024, 4:03 p.m. πŸ”„ Last Modified: Nov. 22, 2025, 12:22 p.m.

6.9

CVSS4.0

CVE-2024-12987 - DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injecti…

πŸ“… Published: Dec. 27, 2024, 4 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 7:53 p.m.

8.6

CVSS3.1

CVE-2024-56509 - changedetection.io has Improper Input Validation Leading to LFR/Path Traversal

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow attackers to perform local file read (LFR) or path traversal attacks. These vulnerabilities occur when user input is …

πŸ“… Published: Dec. 27, 2024, 3:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2024-56508 - File Upload Vulnerability Leading to XSS in LinkAce v1.15.5

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This issue occurs in the "Import Bookmarks" functionality, where malicious HTML files can be uploaded containing JavaScript payloads. These payloads execu…

πŸ“… Published: Dec. 27, 2024, 3:52 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 3:04 p.m.

4.6

CVSS3.1

CVE-2024-56507 - Reflected Cross-Site Scripting (XSS) Vulnerability in LinkAce

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. This issue occurs in the "URL" field of the "Edit Link" module, where user input is not properly sanitized or encoded before bein…

πŸ“… Published: Dec. 27, 2024, 3:50 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 3:04 p.m.

6.9

CVSS4.0

CVE-2024-12986 - DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupptim os command injection

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session lea…

πŸ“… Published: Dec. 27, 2024, 3:31 p.m. πŸ”„ Last Modified: May 28, 2025, 8:21 p.m.

5.3

CVSS4.0

CVE-2024-12985 - Overtek OT-E801G passwd os command injection

A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.cmd?action=test&interface=ppp0.1&ipaddr=8.8.8.8%26%26cat%20/etc/passwd&ipversion=4&sessionKey=test. The manipulation leads to os command injection. Th…

πŸ“… Published: Dec. 27, 2024, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7346 of 34,919
Β« previous page Β» next page
Filters