6.4

CVSS3.1

CVE-2024-5796 - Infinite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via project_url Parame…

The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜project_url’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…

πŸ“… Published: June 28, 2024, 6:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-5788 - Silesia <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode

The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link’ attribute within the theme's Button shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with …

πŸ“… Published: June 28, 2024, 6:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-39350 -

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 …

πŸ“… Published: June 28, 2024, 6:55 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

3.3

CVSS3.1

CVE-2024-30111 - Missing Root Detection vulnerability affects DRYiCE AEX v10

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially leading to data breaches…

πŸ“… Published: June 28, 2024, 6:39 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 6:43 p.m.

7.5

CVSS3.1

CVE-2024-39348 -

Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.

πŸ“… Published: June 28, 2024, 6:30 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 1:47 p.m.

5.9

CVSS3.1

CVE-2024-39347 -

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.

πŸ“… Published: June 28, 2024, 6:30 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 1:46 p.m.

3.7

CVSS3.1

CVE-2024-30110 - Lack of input validation vulnerability affects DRYiCE AEX v10

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.

πŸ“… Published: June 28, 2024, 6:25 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 6:44 p.m.

4.9

CVSS3.1

CVE-2024-39352 -

A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7…

πŸ“… Published: June 28, 2024, 6:07 a.m. πŸ”„ Last Modified: April 10, 2025, 6:14 p.m.

7.2

CVSS3.1

CVE-2024-39351 -

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models wi…

πŸ“… Published: June 28, 2024, 6:07 a.m. πŸ”„ Last Modified: April 10, 2025, 6:38 p.m.

9.8

CVSS3.1

CVE-2024-39349 -

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camer…

πŸ“… Published: June 28, 2024, 6:03 a.m. πŸ”„ Last Modified: April 10, 2025, 7:03 p.m.
Total resulsts: 349182
Page 9308 of 34,919
Β« previous page Β» next page
Filters