3.5

CVSS3.1

CVE-2024-22733 -

TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 9:35 p.m.

8.8

CVSS3.1

CVE-2024-48217 -

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 3:35 p.m.

8.8

CVSS3.1

CVE-2024-51377 -

An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 14, 2024, 11:23 p.m.

8

CVSS3.1

CVE-2024-51252 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 8:54 p.m.

8

CVSS3.1

CVE-2024-51245 -

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 7:28 p.m.

7.5

CVSS3.1

CVE-2024-48270 -

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 5:32 p.m.

9.1

CVSS3.1

CVE-2024-28265 -

IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: July 11, 2025, 1:58 p.m.

7.1

CVSS3.1

CVE-2024-27524 -

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 7:06 p.m.

8.1

CVSS3.1

CVE-2024-51431 -

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 9:37 p.m.

5.7

CVSS3.1

CVE-2024-51399 -

Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches and identity theft.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 6:35 p.m.
Total resulsts: 344058
Page 7559 of 34,406
ยซ previous page ยป next page
Filters