6.3

CVSS3.1

CVE-2024-46548 -

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-28809 -

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: May 30, 2025, 2:50 p.m.

4.3

CVSS3.1

CVE-2024-35495 -

An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-28808 -

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: May 30, 2025, 2:49 p.m.

6.5

CVSS3.1

CVE-2024-28807 -

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: May 30, 2025, 2:49 p.m.

3.3

CVSS3.1

CVE-2024-28811 -

An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: May 30, 2025, 2:50 p.m.

10

CVSS3.1

CVE-2024-42017 -

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the applicatio…

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46511 -

LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and CredsGenFunction function.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-46313 -

TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 6:32 p.m.

6.3

CVSS3.1

CVE-2024-46540 -

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.

πŸ“… Published: Sept. 30, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 3:57 p.m.
Total resulsts: 349182
Page 8439 of 34,919
Β« previous page Β» next page
Filters