6.9

CVSS4.0

CVE-2024-47903 -

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices allows to write arbitrary fiโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 2:21 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 3:54 p.m.

6.9

CVSS4.0

CVE-2024-47902 -

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET reโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 2:21 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 3:48 p.m.

10

CVSS4.0

CVE-2024-47901 -

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input โ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 2:21 p.m. ๐Ÿ”„ Last Modified: Oct. 30, 2024, 3:39 p.m.

8.7

CVSS4.0

CVE-2024-10281 - Tenda RX9/RX9 Pro SetStaticRouteCfg sub_42EEE0 stack-based overflow

A vulnerability classified as critical has been found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected is the function sub_42EEE0 of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotelyโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 2 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 1:52 p.m.

6.1

CVSS3.1

CVE-2024-10250 - Nioland <= 1.2.6 - Reflected Cross-Site Scripting via s

The Nioland theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the โ€˜sโ€™ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pagesโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 1:58 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:28 p.m.

6.3

CVSS3.1

CVE-2024-50050 -

Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.

๐Ÿ“… Published: Oct. 23, 2024, 1:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2024-10280 - Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer derefereโ€ฆ

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereferโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 1:31 p.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 2:03 p.m.

0.0

CVE-2024-10305 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Oct. 23, 2024, 1:30 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

5.3

CVSS4.0

CVE-2024-10279 - ESAFENET CDG PrintPolicyService.java sql injection

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code of the file /com/esafenet/servlet/policy/PrintPolicyService.java. The manipulation of the argument policyId leads to sql injection. The attack can be initiated remotely. The exploiโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 1 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2024, 10:14 p.m.

5.3

CVSS4.0

CVE-2024-10278 - ESAFENET CDG ReUserOrganiseService.java sql injection

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the file /com/esafenet/servlet/user/ReUserOrganiseService.java. The manipulation of the argument userId leads to sql injection. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: Oct. 23, 2024, 1 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2024, 10:11 p.m.
Total resulsts: 349182
Page 8171 of 34,919
ยซ previous page ยป next page
Filters