8

CVSS3.1

CVE-2024-51248 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 7:28 p.m.

7.5

CVSS3.1

CVE-2024-40490 -

An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-51406 -

Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: June 11, 2025, 2:15 p.m.

6.2

CVSS3.1

CVE-2024-51407 -

Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 8:26 p.m.

7.5

CVSS3.1

CVE-2024-48353 -

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: March 7, 2025, 9:15 p.m.

8

CVSS3.1

CVE-2024-51247 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 7:28 p.m.

6.5

CVSS3.1

CVE-2024-51398 -

Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-51244 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2024, 7:28 p.m.

6.1

CVSS3.1

CVE-2024-48410 -

Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2024-51399 -

Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches and identity theft.

๐Ÿ“… Published: Nov. 1, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8071 of 34,919
ยซ previous page ยป next page
Filters