8.7

CVSS4.0

CVE-2024-7581 - Tenda A301 WifiBasicSet formWifiBasicSet stack-based overflow

A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit h…

📅 Published: Aug. 7, 2024, 3 p.m. 🔄 Last Modified: Aug. 7, 2024, 7:59 p.m.

5.3

CVSS4.0

CVE-2024-7580 - Alien Technology ALR-F800 system.html os command injection

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/system.html. The manipulation of the argument uploadedFile with the input ;whoami leads to os command injection. The attac…

📅 Published: Aug. 7, 2024, 2:31 p.m. 🔄 Last Modified: Aug. 22, 2024, 3:40 p.m.

5.3

CVSS4.0

CVE-2024-7579 - Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os com…

📅 Published: Aug. 7, 2024, 2 p.m. 🔄 Last Modified: Aug. 28, 2024, 6:26 p.m.

8.3

CVSS3.1

CVE-2024-7143 - Pulpcore: rbac permissions incorrectly assigned in tasks that create objects

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticat…

📅 Published: Aug. 7, 2024, 1:50 p.m. 🔄 Last Modified: March 20, 2026, 3:15 a.m.

6.9

CVSS4.0

CVE-2024-7578 - Alien Technology ALR-F800 cmd.php improper authorization

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the argument cmd leads to improper authorization. It is possible to launch the attack remotely. The exploit…

📅 Published: Aug. 7, 2024, 1 p.m. 🔄 Last Modified: Aug. 28, 2024, 6:27 p.m.

4.9

CVSS3.1

CVE-2024-7355 - Organization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_inp…

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

📅 Published: Aug. 7, 2024, 12:30 p.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

5.4

CVSS3.1

CVE-2024-7353 - Accept Stripe Payments <= 2.0.86 - Authenticated (Contributor+) Stored Cross-Site Scripting via acc…

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: Aug. 7, 2024, 11:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2024-6522 - Modern Events Calendar <= 7.12.1 - Authenticated (Subscriber+) Server Side Request Forgery

The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitra…

📅 Published: Aug. 7, 2024, 11 a.m. 🔄 Last Modified: April 8, 2026, 4:32 p.m.

7.1

CVSS4.0

CVE-2024-7267 - Internal infrastructure data leak in EZD RP

Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6

📅 Published: Aug. 7, 2024, 10:59 a.m. 🔄 Last Modified: March 17, 2025, 9:15 a.m.

7.1

CVSS4.0

CVE-2024-7266 - Users listing in EZD RP

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 befor…

📅 Published: Aug. 7, 2024, 10:58 a.m. 🔄 Last Modified: March 25, 2025, 2:31 p.m.
Total resulsts: 349182
Page 8924 of 34,919
« previous page » next page
Filters