4.3

CVSS4.0

CVE-2024-6051 - Cross Application Scripting in Redlink SDK

Cross Application Scripting vulnerability in Vercom S.A. Redlink SDKΒ in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.

πŸ“… Published: Sept. 30, 2024, 12:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-47641 - WordPress Confetti Fall Animation plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel Confetti Fall Animation confetti-fall-animation allows Stored XSS.This issue affects Confetti Fall Animation: from n/a through <= 1.3.0.

πŸ“… Published: Sept. 30, 2024, 12:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.1

CVSS3.1

CVE-2024-45772 - Apache Lucene Replicator: Security Vulnerability in Lucene Replicator - Deserialization Issue

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected. Users ar…

πŸ“… Published: Sept. 30, 2024, 8:51 a.m. πŸ”„ Last Modified: May 15, 2025, 4:53 p.m.

7.5

CVSS3.0

CVE-2024-6394 - Local File Inclusion in parisneo/lollms-webui

A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary fil…

πŸ“… Published: Sept. 30, 2024, 8:09 a.m. πŸ”„ Last Modified: July 9, 2025, 2:18 p.m.

7.2

CVSS3.1

CVE-2024-8459 - PLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwords

Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.

πŸ“… Published: Sept. 30, 2024, 7:59 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 2:42 p.m.

2.4

CVSS3.0

CVE-2024-42496 -

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.

πŸ“… Published: Sept. 30, 2024, 7:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-41999 -

Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change the device's settin…

πŸ“… Published: Sept. 30, 2024, 7:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-8458 - PLANET Technology switch devices - Cross-site Request Forgery

Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such…

πŸ“… Published: Sept. 30, 2024, 7:45 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 2:42 p.m.

4.8

CVSS3.1

CVE-2024-8457 - PLANET Technology switch devices - Stored cross-site scripting (XSS) in the User Management

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

πŸ“… Published: Sept. 30, 2024, 7:39 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 2:45 p.m.

9.8

CVSS3.1

CVE-2024-8456 - PLANET Technology switch devices - Missing Authentication for multiple HTTP routes

Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.

πŸ“… Published: Sept. 30, 2024, 7:35 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 2:45 p.m.
Total resulsts: 349182
Page 8436 of 34,919
Β« previous page Β» next page
Filters