9.8

CVSS3.1

CVE-2024-12356 - Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

πŸ“… Published: Dec. 17, 2024, 4:29 a.m. πŸ”„ Last Modified: Oct. 24, 2025, 1:44 p.m.

5.9

CVSS3.1

CVE-2021-26279 - Information disclosure vulnerability in Weather module

Some parameters of the weather module are improperly stored, leaking some sensitive information.

πŸ“… Published: Dec. 17, 2024, 3:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2021-26278 - Sensitive information leakage vulnerability in wifi module

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

πŸ“… Published: Dec. 17, 2024, 3:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2020-12487 - Command Execution Vulnerability in ABE service

Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

πŸ“… Published: Dec. 17, 2024, 2:53 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2020-12484 -

When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.

πŸ“… Published: Dec. 17, 2024, 2:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12239 - PowerPack Lite for Beaver Builder <= 1.3.0.5 - Reflected Cross-Site Scripting via Navigate Parameter

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

πŸ“… Published: Dec. 17, 2024, 1:45 a.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.

9.4

CVSS3.1

CVE-2024-10205 - Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Cent…

Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.…

πŸ“… Published: Dec. 17, 2024, 1:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-36832 -

A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully constructed HTTP request, it w…

πŸ“… Published: Dec. 17, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 1:21 p.m.

5.4

CVSS3.1

CVE-2024-55056 -

A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

πŸ“… Published: Dec. 17, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 4:18 p.m.

5.3

CVSS3.1

CVE-2024-36831 -

A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.

πŸ“… Published: Dec. 17, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 3:21 p.m.
Total resulsts: 349182
Page 7437 of 34,919
Β« previous page Β» next page
Filters