9.8
CVE-2024-23601 -
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
9.8
CVE-2024-35324 -
Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
6.5
CVE-2024-33849 -
ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
5.3
CVE-2024-35400 -
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules
8.8
CVE-2024-35399 -
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
5.4
CVE-2024-4429 - Cross Site Request Forgery vulnerability in iManager
Cross-Site Request Forgery vulnerabilityย has been discovered in OpenTextโข iManager 3.2.6.0200. This could lead to sensitive information disclosure.
7.8
CVE-2024-3969 - XML External Entity injection vulnerability in iManager
XML External Entity injection vulnerability foundย in OpenTextโข iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
9.8
CVE-2024-35398 -
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.
8.8
CVE-2024-35397 -
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
6.4
CVE-2024-2451 - Improper fingerprint validation in the TeamViewer Client
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading.