8

CVSS3.1

CVE-2024-46328 -

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: May 29, 2025, 5:21 p.m.

5.4

CVSS3.1

CVE-2024-45986 -

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account inform…

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 9:16 p.m.

7.3

CVSS3.1

CVE-2024-40507 -

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: April 23, 2025, 3:57 p.m.

6.5

CVSS3.1

CVE-2024-45987 -

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent …

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

7.5

CVSS3.1

CVE-2024-44860 -

An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 3:38 p.m.

8.8

CVSS3.1

CVE-2024-45980 -

A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-46330 -

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: June 4, 2025, 4:16 p.m.

8

CVSS3.1

CVE-2024-46628 -

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: Oct. 4, 2024, 5:18 p.m.

4.7

CVSS3.1

CVE-2024-45984 -

A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will be executed when the Donor List is viewed.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: May 14, 2025, 3:50 p.m.

8.8

CVSS3.1

CVE-2024-45979 -

A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

πŸ“… Published: Sept. 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8471 of 34,919
Β« previous page Β» next page
Filters