8.1

CVSS3.1

CVE-2024-9302 - App Builder – Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Ac…

The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to…

πŸ“… Published: Oct. 25, 2024, 6:51 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

6.2

CVSS3.1

CVE-2024-48870 -

Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:34 p.m.

7.4

CVSS3.1

CVE-2024-47801 -

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:34 p.m.

7.4

CVSS3.1

CVE-2024-47549 -

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:40 p.m.

9.1

CVSS3.1

CVE-2024-47406 -

Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:36 p.m.

8.1

CVSS3.1

CVE-2024-47005 -

Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:36 p.m.

5.3

CVSS3.1

CVE-2024-45842 -

Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Dec. 3, 2024, 5:11 p.m.

4.9

CVSS3.1

CVE-2024-45829 -

Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:38 p.m.

7.5

CVSS3.1

CVE-2024-43424 -

Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:39 p.m.

7.5

CVSS3.1

CVE-2024-42420 -

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

πŸ“… Published: Oct. 25, 2024, 6:18 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 7:39 p.m.
Total resulsts: 349182
Page 8145 of 34,919
Β« previous page Β» next page
Filters