5.3
CVE-2024-8080 - SourceCodester Online Health Care System search.php sql injection
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20…
8.7
CVE-2024-8079 - TOTOLINK AC1200 T8 exportOvpn buffer overflow
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to buffer overflow. The attack may be initiated remotely. NOTE: The vendor was contacted early about this disclosure but did not r…
6.9
CVE-2023-7260 - A path traversal vulnerability has been discovered in OpenText™ CX-E Voice.
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
8.7
CVE-2024-8078 - TOTOLINK AC1200 T8 setTracerouteCfg buffer overflow
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to buffer overflow. The attack can be initiated remotely. NOTE: The vendor was contacted early about this disclos…
5.3
CVE-2024-8077 - TOTOLINK AC1200 T8 setTracerouteCfg os command injection
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disc…
8.7
CVE-2024-8076 - TOTOLINK AC1200 T8 setDiagnosisCfg buffer overflow
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to buffer overflow. The attack may be launched remotely. NOTE: The vendor was contacted early about this disclosure but di…
8.7
CVE-2024-42418 - Avtec Outpost Use of Hard-coded Cryptographic Key
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
8.7
CVE-2024-39776 - Avtec Outpost Storage of File with Sensitive Data Under Web Root
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
5.3
CVE-2024-8075 - TOTOLINK AC1200 T8 setDiagnosisCfg os command injection
A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads to os command injection. The attack can be launched remotely. NOTE: The vendor was contacted early about this…
7.2
CVE-2024-39717 -
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon)…