9

CVSS3.1

CVE-2024-28038 -

The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11202 - Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Short…

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec…

📅 Published: Nov. 26, 2024, 7:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-9504 - Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scriptin…

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in…

📅 Published: Nov. 26, 2024, 7:31 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.8

CVSS3.1

CVE-2024-8160 -

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating…

📅 Published: Nov. 26, 2024, 7:27 a.m. 🔄 Last Modified: Jan. 22, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2024-8772 -

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited afte…

📅 Published: Nov. 26, 2024, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-47257 -

Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlighted flaw for products that are still under AXIS OS software su…

📅 Published: Nov. 26, 2024, 7:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-6831 -

Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security advisory for …

📅 Published: Nov. 26, 2024, 7:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-6749 -

Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured this flaw does not apply. Axis has release…

📅 Published: Nov. 26, 2024, 7:07 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2024-6476 -

Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted flaw. Please refer to the Axis security adv…

📅 Published: Nov. 26, 2024, 7 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-10857 - Product Input Fields for WooCommerce <= 1.9 - Authenticated (Contributor+) Arbitrary File Read

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributo…

📅 Published: Nov. 26, 2024, 6:43 a.m. 🔄 Last Modified: April 8, 2026, 5:29 p.m.
Total resulsts: 349182
Page 7704 of 34,919
« previous page » next page
Filters