4.3

CVSS3.1

CVE-2024-41729 - Information Disclosure vulnerability in the SAP NetWeaver BW (BEx Analyzer)

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.

πŸ“… Published: Sept. 10, 2024, 2:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-8478 - Affiliate Super Assistent <= 1.5.3 - Unauthenticated Arbitrary Shortcode Execution

The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possibl…

πŸ“… Published: Sept. 10, 2024, 2:05 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

8.8

CVSS3.1

CVE-2024-8268 - Frontend Dashboard <= 2.2.4 - Authenticated (Subscriber+) Arbitrary Function Call

The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level…

πŸ“… Published: Sept. 10, 2024, 2:05 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

9.8

CVSS3.1

CVE-2024-6342 -

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sendin…

πŸ“… Published: Sept. 10, 2024, 1:55 a.m. πŸ”„ Last Modified: Jan. 22, 2025, 10:31 p.m.

5.3

CVSS3.1

CVE-2024-38270 -

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid s…

πŸ“… Published: Sept. 10, 2024, 1:20 a.m. πŸ”„ Last Modified: Sept. 18, 2024, 6:23 p.m.

8

CVSS3.1

CVE-2024-44667 -

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

πŸ“… Published: Sept. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-44815 -

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

πŸ“… Published: Sept. 10, 2024, midnight πŸ”„ Last Modified: Sept. 25, 2024, 7:17 p.m.

7.5

CVSS3.1

CVE-2023-37232 -

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

πŸ“… Published: Sept. 10, 2024, midnight πŸ”„ Last Modified: Sept. 18, 2024, 3:55 p.m.

6.1

CVSS3.1

CVE-2024-44676 -

eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

πŸ“… Published: Sept. 10, 2024, midnight πŸ”„ Last Modified: April 14, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-44872 -

A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: Sept. 10, 2024, midnight πŸ”„ Last Modified: Sept. 13, 2024, 3:26 p.m.
Total resulsts: 349182
Page 8625 of 34,919
Β« previous page Β» next page
Filters