5.3

CVSS3.1

CVE-2024-49214 - haproxy: Spoofed IP Bypass in HAProxy QUIC Listener 0-RTT Sessions

QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: July 12, 2025, 10:31 p.m.

4.3

CVSS3.1

CVE-2024-46528 -

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 28, 2025, 4:15 p.m.

7.3

CVSS3.1

CVE-2024-48255 -

Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 16, 2024, 2:26 p.m.

8.4

CVSS3.1

CVE-2024-35519 -

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2024-48799 -

An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: March 24, 2025, 5:15 p.m.

7.3

CVSS3.1

CVE-2024-48249 -

Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 7:41 p.m.

7.3

CVSS3.1

CVE-2024-48257 -

Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 16, 2024, 2:24 p.m.

5.9

CVSS3.1

CVE-2024-48793 -

An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 15, 2024, 9:35 p.m.

6.1

CVSS3.1

CVE-2024-48821 -

Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: March 24, 2025, 6:15 p.m.

5.3

CVSS3.1

CVE-2024-48795 -

An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 16, 2024, 8:35 p.m.
Total resulsts: 343183
Page 7704 of 34,319
ยซ previous page ยป next page
Filters