7.8

CVSS3.1

CVE-2024-51141 -

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: June 17, 2025, 1:07 a.m.

7.5

CVSS3.1

CVE-2024-50654 -

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: Nov. 21, 2024, 7:15 p.m.

5.9

CVSS3.1

CVE-2024-24455 -

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-24454 -

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-50653 -

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: March 13, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-44758 -

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: Oct. 1, 2025, 4:02 p.m.

9.1

CVSS3.1

CVE-2024-51164 -

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: June 24, 2025, 2:37 p.m.

5.9

CVSS3.1

CVE-2024-24457 -

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-24453 -

An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-24449 -

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7868 of 34,919
« previous page » next page
Filters