6.5

CVSS3.1

CVE-2024-34352 - Arbitrary file write vulnerability in 1Panel

1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol …

πŸ“… Published: May 9, 2024, 2:38 p.m. πŸ”„ Last Modified: Feb. 7, 2025, 2:44 a.m.

5.3

CVSS4.0

CVE-2024-4678 - Campcodes Complete Web-Based School Management System find_friends.php cross site scripting

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The att…

πŸ“… Published: May 9, 2024, 2:31 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:06 p.m.

8.1

CVSS3.1

CVE-2024-32655 - Npgsql Vulnerable to SQL Injection via Protocol Message Size Overflow

Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This…

πŸ“… Published: May 9, 2024, 2:29 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 9:15 p.m.

6.1

CVSS3.1

CVE-2024-34074 - Frappe vuilnerable to an open redirect on login page

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

πŸ“… Published: May 9, 2024, 2:25 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:37 p.m.

7.3

CVSS3.1

CVE-2024-34210 -

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.

πŸ“… Published: May 9, 2024, 2:22 p.m. πŸ”„ Last Modified: April 9, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2024-34211 -

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

πŸ“… Published: May 9, 2024, 2:20 p.m. πŸ”„ Last Modified: April 9, 2025, 2:15 p.m.

6.8

CVSS3.1

CVE-2024-32874 - In Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Servi…

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. This is due to no l…

πŸ“… Published: May 9, 2024, 2:20 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:15 a.m.

7.3

CVSS3.1

CVE-2024-34212 -

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.

πŸ“… Published: May 9, 2024, 2:17 p.m. πŸ”„ Last Modified: April 9, 2025, 2:15 p.m.

8.6

CVSS3.1

CVE-2024-34219 -

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

πŸ“… Published: May 9, 2024, 2:07 p.m. πŸ”„ Last Modified: April 4, 2025, 2:47 p.m.

6.2

CVSS3.1

CVE-2024-31803 -

Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.

πŸ“… Published: May 9, 2024, 1:56 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:47 p.m.
Total resulsts: 343975
Page 9408 of 34,398
Β« previous page Β» next page
Filters