9.8

CVSS3.1

CVE-2024-45321 - perl-App-cpanminus: Insecure HTTP in App::cpanminus Allows Code Execution Vulnerability

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

πŸ“… Published: Aug. 27, 2024, midnight πŸ”„ Last Modified: Dec. 5, 2024, 6:47 p.m.

8

CVSS3.1

CVE-2024-45264 -

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

πŸ“… Published: Aug. 27, 2024, midnight πŸ”„ Last Modified: Aug. 30, 2024, 3:02 p.m.

8.8

CVSS3.1

CVE-2024-44340 -

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

πŸ“… Published: Aug. 27, 2024, midnight πŸ”„ Last Modified: Aug. 30, 2024, 2:56 p.m.

8.8

CVSS3.1

CVE-2024-41622 -

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

πŸ“… Published: Aug. 27, 2024, midnight πŸ”„ Last Modified: Aug. 30, 2024, 2:55 p.m.

8

CVSS3.1

CVE-2022-39997 -

A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

πŸ“… Published: Aug. 27, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.0

CVE-2024-45036 - Improper Access Control Vulnerability When Accessing a Maliciously Crafted Tophat Link

Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability allows Tophat to send this token to the attacker's server wit…

πŸ“… Published: Aug. 26, 2024, 10:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-43798 - Chisel AUTH environment variable not respected in server entrypoint

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to set credentials, which allows any unauthenticated user to connect, even if credentials were set. Anyone running the Chisel server that is u…

πŸ“… Published: Aug. 26, 2024, 10:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-39628 - WordPress Ninja Forms plugin <= 3.8.6 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.

πŸ“… Published: Aug. 26, 2024, 8:58 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:42 p.m.

4.3

CVSS3.1

CVE-2024-39641 - WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.

πŸ“… Published: Aug. 26, 2024, 8:56 p.m. πŸ”„ Last Modified: Sept. 18, 2024, 4:57 p.m.

5.4

CVSS3.1

CVE-2024-39645 - WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

πŸ“… Published: Aug. 26, 2024, 8:55 p.m. πŸ”„ Last Modified: Sept. 18, 2024, 4:46 p.m.
Total resulsts: 347742
Page 8582 of 34,775
Β« previous page Β» next page
Filters