8.1

CVSS3.1

CVE-2024-48325 -

Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unau…

📅 Published: Nov. 6, 2024, midnight 🔄 Last Modified: June 24, 2025, 4:31 p.m.

5.9

CVSS3.1

CVE-2024-9681 - HSTS subdomain overwrites parent cache entry

When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hos…

📅 Published: Nov. 6, 2024, midnight 🔄 Last Modified: Nov. 3, 2025, 9:18 p.m.

5.4

CVSS3.1

CVE-2024-50637 -

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

📅 Published: Nov. 6, 2024, midnight 🔄 Last Modified: June 24, 2025, 4:56 p.m.

6.5

CVSS3.1

CVE-2024-51409 -

Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format to a router running the corresponding version of the firmware.

📅 Published: Nov. 6, 2024, midnight 🔄 Last Modified: April 11, 2025, 3:04 p.m.

7.5

CVSS3.1

CVE-2024-10028 - Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive …

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated…

📅 Published: Nov. 5, 2024, 11:28 p.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

6.8

CVSS3.1

CVE-2024-47464 - Authenticated Path Traversal Vulnerability Leads to a Remote Unauthorized Access to Files

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote una…

📅 Published: Nov. 5, 2024, 11:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-47463 - Arbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Com…

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operat…

📅 Published: Nov. 5, 2024, 10:59 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-47462 - Arbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Com…

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operat…

📅 Published: Nov. 5, 2024, 10:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-47461 - Authenticated Arbitrary Remote Command Execution (RCE) in Instant AOS-8 and AOS-10

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fu…

📅 Published: Nov. 5, 2024, 10:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2024-47460 - Unauthenticated Command Injection Vulnerability in the CLI Service Accessed by the PAPI Protocol

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the abilit…

📅 Published: Nov. 5, 2024, 10:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8010 of 34,919
« previous page » next page
Filters