8.7

CVSS4.0

CVE-2024-50054 - mySCADA myPRO Path Traversal

The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.

πŸ“… Published: Nov. 22, 2024, 10:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2024-47138 - mySCADA myPRO Missing Authentication for Critical Function

The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

πŸ“… Published: Nov. 22, 2024, 10:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2024-45369 - mySCADA myPRO Improper Authentication

The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.

πŸ“… Published: Nov. 22, 2024, 10:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2024-52034 - mySCADA myPRO OS Command Injection

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

πŸ“… Published: Nov. 22, 2024, 10:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2024-47407 - mySCADA myPRO OS Command Injection

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

πŸ“… Published: Nov. 22, 2024, 10:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-11630 - E-Lins H685/H685f/H700/H720/H750/H820/H820Q/H820Q0/H900 OEM Backend hard-coded credentials

A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulnerability affects unknown code of the component OEM Backend. The manipulation leads to hard-coded credentials. The attack can be initiated remotely. Th…

πŸ“… Published: Nov. 22, 2024, 10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-9114 - FastStone Image Viewer GIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

FastStone Image Viewer GIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target mu…

πŸ“… Published: Nov. 22, 2024, 9:34 p.m. πŸ”„ Last Modified: Nov. 26, 2024, 8:58 p.m.

7.8

CVSS3.1

CVE-2024-9113 - FastStone Image Viewer TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

FastStone Image Viewer TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target mu…

πŸ“… Published: Nov. 22, 2024, 9:33 p.m. πŸ”„ Last Modified: Dec. 19, 2024, 6:15 p.m.

7.8

CVSS3.1

CVE-2024-9112 - FastStone Image Viewer PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

FastStone Image Viewer PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target mu…

πŸ“… Published: Nov. 22, 2024, 9:33 p.m. πŸ”„ Last Modified: Dec. 19, 2024, 6:15 p.m.

6.8

CVSS3.1

CVE-2024-8360 - Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability

Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment systems. Authentication is not required to exploit this vulnerabilit…

πŸ“… Published: Nov. 22, 2024, 9:33 p.m. πŸ”„ Last Modified: Dec. 4, 2024, 7:32 p.m.
Total resulsts: 346643
Page 7467 of 34,665
Β« previous page Β» next page
Filters