6.1

CVSS3.1

CVE-2024-8586 - Uniong WebITR - Open Redirect

WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.

πŸ“… Published: Sept. 9, 2024, 3:07 a.m. πŸ”„ Last Modified: Sept. 16, 2024, 1:28 p.m.

6.5

CVSS3.1

CVE-2024-8585 - LEARNING DIGITAL Orca HCM - Arbitrary File Download

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.

πŸ“… Published: Sept. 9, 2024, 3:03 a.m. πŸ”„ Last Modified: Sept. 11, 2024, 3:53 p.m.

9.8

CVSS3.1

CVE-2024-8584 - LEARNING DIGITAL Orca HCM - Missing Authentication

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

πŸ“… Published: Sept. 9, 2024, 2:57 a.m. πŸ”„ Last Modified: Feb. 21, 2025, 4:54 p.m.

8.8

CVSS3.1

CVE-2024-44334 -

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-24510 -

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 8:17 p.m.

4.4

CVSS3.1

CVE-2024-27368 -

An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_received_frame_ind(), there is no input validation check on a le…

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 9:15 p.m.

9.8

CVSS3.1

CVE-2024-44411 -

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 1:14 p.m.

9.8

CVSS3.1

CVE-2024-44849 -

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: July 1, 2025, 8:37 p.m.

7.5

CVSS3.1

CVE-2024-44375 -

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2024-44335 -

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

πŸ“… Published: Sept. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8631 of 34,919
Β« previous page Β» next page
Filters