5.3

CVSS4.0

CVE-2024-8131 - D-Link DNS-1550-04 HTTP POST Request apkg_mgr.cgi module_enable_disable command injection

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this …

πŸ“… Published: Aug. 24, 2024, 5:31 p.m. πŸ”„ Last Modified: Aug. 27, 2024, 3:34 p.m.

5.3

CVSS4.0

CVE-2024-8130 - D-Link DNS-1550-04 HTTP POST Request s3.cgi cgi_s3 command injection

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by …

πŸ“… Published: Aug. 24, 2024, 4:31 p.m. πŸ”„ Last Modified: Aug. 27, 2024, 3:34 p.m.

5.3

CVSS4.0

CVE-2024-8129 - D-Link DNS-1550-04 HTTP POST Request s3.cgi cgi_s3_modify command injection

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected …

πŸ“… Published: Aug. 24, 2024, 3:31 p.m. πŸ”„ Last Modified: Aug. 27, 2024, 3:33 p.m.

8.8

CVSS3.1

CVE-2024-7656 - Image Hotspot by DevVN <= 1.2.5 - Authenticated (Author+) PHP Object Injection

The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of untrusted input in the 'devvn_ihotspot_shortcode_func' function. This makes it possible for authenticated attackers, with Author-level access and …

πŸ“… Published: Aug. 24, 2024, 11:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-8128 - D-Link DNS-1550-04 HTTP POST Request webfile_mgr.cgi cgi_add_zip command injection

A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This…

πŸ“… Published: Aug. 24, 2024, 11:31 a.m. πŸ”„ Last Modified: Aug. 27, 2024, 3:32 p.m.

6.8

CVSS3.1

CVE-2022-43915 - IBM App Connect Enterprise Certified Container

IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, and 12.1 does not limit calls to unshare in running Pods. This can allow a user with privileged access to execute commands in a running Pod to ele…

πŸ“… Published: Aug. 24, 2024, 11:22 a.m. πŸ”„ Last Modified: Sept. 21, 2024, 10:15 a.m.

5.3

CVSS4.0

CVE-2024-8127 - D-Link DNS-1550-04 HTTP POST Request webfile_mgr.cgi cgi_unzip command injection

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability af…

πŸ“… Published: Aug. 24, 2024, 9:31 a.m. πŸ”„ Last Modified: Aug. 27, 2024, 2:53 p.m.

7.2

CVSS3.1

CVE-2024-7351 - Simple Job Board <= 2.12.3 - Authenticated (Editor+) PHP Object Injection

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP …

πŸ“… Published: Aug. 24, 2024, 7:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

5.3

CVSS3.1

CVE-2024-6499 - WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabi…

πŸ“… Published: Aug. 24, 2024, 3:29 a.m. πŸ”„ Last Modified: April 8, 2026, 5:35 p.m.

5

CVSS3.1

CVE-2024-6631 - ImageRecycle pdf & image compression <= 3.1.14 - Missing Authorization in Several AJAX Actions

The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with Subscriber-level access a…

πŸ“… Published: Aug. 24, 2024, 2:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:32 p.m.
Total resulsts: 349182
Page 8744 of 34,919
Β« previous page Β» next page
Filters