5.9

CVSS3.1

CVE-2024-35401 -

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

๐Ÿ“… Published: May 28, 2024, 4:22 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 3:45 p.m.

2.7

CVSS3.1

CVE-2024-35403 -

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules

๐Ÿ“… Published: May 28, 2024, 4:21 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 12:01 a.m.

7

CVSS4.0

CVE-2024-30212 - Microchip Harmony 3 Core library allows read and write access to RAM via a SCSI READ or WRITE commaโ€ฆ

If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. The same method works โ€ฆ

๐Ÿ“… Published: May 28, 2024, 4:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-22590 -

The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow Client Hello messages to be overwritten at any time, including after a connection has been established.

๐Ÿ“… Published: May 28, 2024, 4:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-33808 -

A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

๐Ÿ“… Published: May 28, 2024, 3:52 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:14 p.m.

5.4

CVSS3.1

CVE-2024-33807 -

A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.

๐Ÿ“… Published: May 28, 2024, 3:51 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:14 p.m.

9.8

CVSS3.1

CVE-2024-33806 -

A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

๐Ÿ“… Published: May 28, 2024, 3:51 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:18 p.m.

9.8

CVSS3.1

CVE-2024-33805 -

A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

๐Ÿ“… Published: May 28, 2024, 3:50 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:18 p.m.

6.3

CVSS3.1

CVE-2024-33804 -

A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

๐Ÿ“… Published: May 28, 2024, 3:50 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:18 p.m.

5.4

CVSS3.1

CVE-2024-33803 -

A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

๐Ÿ“… Published: May 28, 2024, 3:50 p.m. ๐Ÿ”„ Last Modified: March 25, 2025, 5:18 p.m.
Total resulsts: 347061
Page 9440 of 34,707
ยซ previous page ยป next page
Filters