2

CVSS4.0

CVE-2024-38863 - CSRF token leaked in URL parameters

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.

๐Ÿ“… Published: Oct. 14, 2024, 7:19 a.m. ๐Ÿ”„ Last Modified: Dec. 3, 2024, 4:47 p.m.

5.1

CVSS4.0

CVE-2024-38862 - SNMP and IMPI secrets written to audit log

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.

๐Ÿ“… Published: Oct. 14, 2024, 7:19 a.m. ๐Ÿ”„ Last Modified: Dec. 3, 2024, 4:56 p.m.

9.8

CVSS3.1

CVE-2024-9924 - Hgiga OAKlouds - Arbitrary File Read And Delete

The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .

๐Ÿ“… Published: Oct. 14, 2024, 3:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2024-9923 - TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Move through Path Traversal

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

๐Ÿ“… Published: Oct. 14, 2024, 3:17 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2024, 1:24 p.m.

7.5

CVSS3.1

CVE-2024-9922 - TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversal

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

๐Ÿ“… Published: Oct. 14, 2024, 2:55 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2024, 1:21 p.m.

9.8

CVSS3.1

CVE-2024-9921 - TEAMPLUS TECHNOLOGY Team+ - SQL Injection

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

๐Ÿ“… Published: Oct. 14, 2024, 2:48 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2024, 1:19 p.m.

7.5

CVSS3.1

CVE-2024-48798 -

An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48168 -

A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:06 p.m.

9.8

CVSS3.1

CVE-2024-48153 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 2:37 p.m.

7.3

CVSS3.1

CVE-2024-48259 -

Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

๐Ÿ“… Published: Oct. 14, 2024, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:51 p.m.
Total resulsts: 349182
Page 8301 of 34,919
ยซ previous page ยป next page
Filters