5.5
CVE-2024-5285 - WP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRF
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack
5.4
CVE-2024-4483 - Email Encoder < 2.2.2 - Admin+ Stored XSS
The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting
8.0
CVE-2024-37381 -
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.
8.7
CVE-2024-7185 - TOTOLINK A3600R cstecgi.cgi setWebWlanIdx buffer overflow
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument webWlanIdx leads to buffer overflow. The attack may be launched remotely. The exploโฆ
8.7
CVE-2024-7184 - TOTOLINK A3600R cstecgi.cgi setUrlFilterRules buffer overflow
A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely.โฆ
8.7
CVE-2024-7183 - TOTOLINK A3600R cstecgi.cgi setUploadSetting buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. It is possible to launch the attack remotely. The eโฆ
8.7
CVE-2024-7182 - TOTOLINK A3600R cstecgi.cgi setUpgradeFW buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The attack may be initiated remotely. The eโฆ
5.3
CVE-2024-7181 - TOTOLINK A3600R cstecgi.cgi setTelnetCfg command injection
A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument telnet_enabled leads to command injection. The attack can be initiated remotely. The exโฆ
9.8
CVE-2024-7202 - Simopro Technology WinMatrix3 Web package - SQL Injection
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
8.7
CVE-2024-7180 - TOTOLINK A3600R cstecgi.cgi setPortForwardRules buffer overflow
A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setPortForwardRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument comment leads to buffer overflow. It is possible to initiate the attack remotely. The expโฆ