6.5

CVSS3.1

CVE-2024-50956 -

A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted Modbus message.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-50970 -

A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: Nov. 18, 2024, 8:35 p.m.

6.5

CVSS3.1

CVE-2024-51027 -

Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-45877 -

baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock oth…

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-45878 -

The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-45879 -

The file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerability, an attacker has to be authenticated t…

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-40404 -

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:23 p.m.

9.1

CVSS3.1

CVE-2024-48510 -

Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: May 2, 2025, 10:40 a.m.

6.5

CVSS3.1

CVE-2024-50971 -

A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: Nov. 18, 2024, 8:35 p.m.

7.3

CVSS3.1

CVE-2024-40408 -

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.

πŸ“… Published: Nov. 13, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:24 p.m.
Total resulsts: 349182
Page 7907 of 34,919
Β« previous page Β» next page
Filters