5.4

CVSS3.1

CVE-2024-42766 -

Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Aug. 26, 2024, 5:35 p.m.

8.1

CVSS3.1

CVE-2024-42040 -

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP…

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 3, 2026, 5:17 p.m.

0.0

CVE-2024-42992 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Aug. 26, 2024, 3:15 p.m.

7.3

CVSS3.1

CVE-2024-44386 -

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 4, 2025, 2:37 p.m.

9.1

CVSS3.1

CVE-2024-42914 -

A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and…

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 21, 2025, 2:40 p.m.

7.2

CVSS3.1

CVE-2024-42636 -

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 6:49 p.m.

8

CVSS3.1

CVE-2024-44390 -

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 3:15 p.m.

6.1

CVSS3.1

CVE-2024-42852 -

Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-42523 -

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 21, 2025, 2:42 p.m.

4.8

CVSS3.1

CVE-2024-40111 -

A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any …

πŸ“… Published: Aug. 23, 2024, midnight πŸ”„ Last Modified: April 21, 2025, 2:38 p.m.
Total resulsts: 349182
Page 8753 of 34,919
Β« previous page Β» next page
Filters