8.7
CVE-2024-38308 - Advantech ADAM-5550 Cross-site Scripting
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
6.8
CVE-2024-37187 - Advantech ADAM-5550 Weak Encoding for Password
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
9.2
CVE-2024-22170 - Unchecked buffer in Dynamic DNS client
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
9.8
CVE-2024-8310 - OPW Fuel Management Systems SiteSentinel Missing Authentication for Critical Function
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.
7.1
CVE-2024-9284 - TP-LINK TL-WR841ND popupSiteSurveyRpm.htm stack-based overflow
A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remβ¦
9.3
CVE-2024-8630 - Alisonic Sibylla SQL Injection
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
9.3
CVE-2024-6981 - OMNTEC Proteus Tank Monitoring Missing Authentication for Critical Function
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.
5
CVE-2024-45745 - TopQuadrant TopBraid EDG JavaScript console XXE
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).
3
CVE-2024-45744 - TopQuadrant TopBraid EDG password manager stores external credentials insecurely
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separaβ¦
8.8
CVE-2024-6983 - Remote Code Execution in mudler/localai
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a binary file and execute malicious code. This can lead to the aβ¦