5.1

CVSS4.0

CVE-2024-7218 - SourceCodester/Campcodes School Log Management System ajax.php cross site scripting

A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The exploit has…

πŸ“… Published: July 30, 2024, 5 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:07 p.m.

5.3

CVSS4.0

CVE-2024-7217 - TOTOLINK CA300-PoE cstecgi.cgi loginauth buffer overflow

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has b…

πŸ“… Published: July 30, 2024, 4:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

2.1

CVSS4.0

CVE-2024-7216 - TOTOLINK LR1200 shadow.sample hard-coded password

A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknown part of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The complexity of an attack is rather high. The exploitability is told to be difficult…

πŸ“… Published: July 30, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

5.3

CVSS4.0

CVE-2024-7215 - TOTOLINK LR1200 cstecgi.cgi NTPSyncWithHost command injection

A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832 and classified as critical. Affected by this issue is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument host_time leads to command injection. The attack may be launched remotely. The exploit has …

πŸ“… Published: July 30, 2024, 3:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

5.3

CVSS4.0

CVE-2024-7214 - TOTOLINK LR350 cstecgi.cgi setWanCfg command injection

A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. Th…

πŸ“… Published: July 30, 2024, 3 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

8.7

CVSS4.0

CVE-2024-7213 - TOTOLINK A7000R cstecgi.cgi setWizardCfg buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504. Affected is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit ha…

πŸ“… Published: July 30, 2024, 2:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

8.7

CVSS4.0

CVE-2024-7212 - TOTOLINK A7000R cstecgi.cgi loginauth buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504. This issue affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack may be initiated remotely. The explo…

πŸ“… Published: July 30, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

7.1

CVSS3.1

CVE-2024-41305 -

A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

5.5

CVSS3.1

CVE-2024-42139 - ice: Fix improper extts handling

In the Linux kernel, the following vulnerability has been resolved: ice: Fix improper extts handling Extts events are disabled and enabled by the application ts2phc. However, in case where the driver is removed when the application is running, a specific extts event remains enabled and can cause …

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:23 a.m.

5.5

CVSS3.1

CVE-2024-42101 - drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes In nouveau_connector_get_modes(), the return value of drm_mode_duplicate() is assigned to mode, which will lead to a possible NULL pointer dereference on fa…

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.
Total resulsts: 349182
Page 9002 of 34,919
Β« previous page Β» next page
Filters