7.5

CVSS3.1

CVE-2024-24426 -

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-52616 - Avahi: avahi wide-area dns predictable transaction ids

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-51142 -

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 2:29 a.m.

5.3

CVSS3.1

CVE-2024-51037 -

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 16, 2025, 1:35 p.m.

7.5

CVSS3.1

CVE-2024-44759 -

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 4:03 p.m.

7.8

CVSS3.1

CVE-2024-51141 -

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 1:07 a.m.

5.9

CVSS3.1

CVE-2024-24455 -

An invalid memory access when handling a UE Context Release messageย containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allowsย attackers to cause a Denial of Service (DoS) to the cellular networkย by repeatedly initiating connections and sending a crafted payload.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-50654 -

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:15 p.m.

7.5

CVSS3.1

CVE-2024-50653 -

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-44758 -

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

๐Ÿ“… Published: Nov. 15, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 4:02 p.m.
Total resulsts: 344718
Page 7421 of 34,472
ยซ previous page ยป next page
Filters