7.2

CVSS3.1

CVE-2024-11013 -

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management in…

πŸ“… Published: Nov. 29, 2024, 8:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2024-9044 - XML External Entity (XXE) Vulnerability in EasyTax

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

πŸ“… Published: Nov. 29, 2024, 7:40 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-11482 -

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

πŸ“… Published: Nov. 29, 2024, 7:03 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 6:34 p.m.

8.2

CVSS3.1

CVE-2024-11481 -

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.

πŸ“… Published: Nov. 29, 2024, 7:01 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 6:37 p.m.

7.2

CVSS3.1

CVE-2024-11983 - Billion Electric router - OS Command Injection

Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.

πŸ“… Published: Nov. 29, 2024, 6:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-11982 - Billion Electric router - Plaintext Storage of a Password

Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.

πŸ“… Published: Nov. 29, 2024, 6:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-11981 - Billion Electric router - Authentication Bypass

Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

πŸ“… Published: Nov. 29, 2024, 6:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-11980 - Billion Electric router - Missing Authentication

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

πŸ“… Published: Nov. 29, 2024, 6:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-10980 - Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow u…

πŸ“… Published: Nov. 29, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 12:03 a.m.

4.8

CVSS3.1

CVE-2024-10704 - Photo Gallery by 10Web < 1.8.31 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Nov. 29, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 12:07 a.m.
Total resulsts: 349182
Page 7670 of 34,919
Β« previous page Β» next page
Filters