5.4

CVSS3.1

CVE-2024-50419 - WordPress Greenshift plugin <=9.7 - Broken Access Control vulnerability

Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.

πŸ“… Published: Oct. 30, 2024, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.3

CVSS3.1

CVE-2024-50353 - ICG.AspNetCore.Utilities.CloudStorage's Secure Token Durations Different Than Expected

ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with a value other than 1 hour may have generated a URL with a duration that is longer, or shorter than d…

πŸ“… Published: Oct. 30, 2024, 1:57 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 3:15 p.m.

8.1

CVSS3.1

CVE-2024-31151 -

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be f…

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

8.1

CVSS3.1

CVE-2024-28875 -

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be f…

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

8.8

CVSS3.1

CVE-2024-24777 -

A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:59 a.m.

5.3

CVSS3.1

CVE-2024-31152 -

The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lead to network service interruptions.

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:12 a.m.

5.9

CVSS3.1

CVE-2024-32946 -

A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:16 a.m.

9.9

CVSS3.1

CVE-2024-33699 -

The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:17 a.m.

5.3

CVSS3.1

CVE-2024-33603 -

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking …

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:17 a.m.

5.3

CVSS3.1

CVE-2024-33626 -

The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the de…

πŸ“… Published: Oct. 30, 2024, 1:35 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:17 a.m.
Total resulsts: 349182
Page 8081 of 34,919
Β« previous page Β» next page
Filters