6.3

CVSS3.1

CVE-2024-46531 -

phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: April 4, 2025, 2:35 p.m.

9.8

CVSS3.1

CVE-2024-51424 -

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 6:15 a.m.

7.2

CVSS3.1

CVE-2023-52066 -

http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 7:35 p.m.

9.8

CVSS3.1

CVE-2024-51427 -

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 6:15 a.m.

9.8

CVSS3.1

CVE-2024-51298 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

8.8

CVSS3.1

CVE-2024-48271 -

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:06 p.m.

5.2

CVSS3.1

CVE-2024-31973 -

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 1, 2024, 12:57 p.m.

8.8

CVSS3.1

CVE-2024-51300 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

8.8

CVSS3.1

CVE-2024-51299 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

6.1

CVSS3.1

CVE-2024-48648 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.

๐Ÿ“… Published: Oct. 30, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 7:49 p.m.
Total resulsts: 343975
Page 7566 of 34,398
ยซ previous page ยป next page
Filters