3.7

CVSS3.1

CVE-2024-35232 - github.com/huandu/facebook may expose access_token in error message

github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in error message on fail in HTTP request. This issue has been patched in version 2.7.2.

πŸ“… Published: May 24, 2024, 8:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-35374 -

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

πŸ“… Published: May 24, 2024, 8:29 p.m. πŸ”„ Last Modified: June 10, 2025, 5:24 p.m.

9.8

CVSS3.1

CVE-2024-35373 -

Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

πŸ“… Published: May 24, 2024, 8:28 p.m. πŸ”„ Last Modified: June 10, 2025, 5:25 p.m.

7.2

CVSS3.1

CVE-2024-33471 -

An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“… Published: May 24, 2024, 6:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-35388 -

TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

πŸ“… Published: May 24, 2024, 6:08 p.m. πŸ”„ Last Modified: May 30, 2025, 2:13 p.m.

9.8

CVSS3.1

CVE-2024-35387 -

TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

πŸ“… Published: May 24, 2024, 6:05 p.m. πŸ”„ Last Modified: April 4, 2025, 5:03 p.m.

6.5

CVSS3.1

CVE-2024-36049 -

Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally…

πŸ“… Published: May 24, 2024, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2023-46442 -

An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

πŸ“… Published: May 24, 2024, 4:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-34995 -

svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com.cym.controller.UserController#importOver. This vulnerability allows attackers to delete arbitrary files via a crafted POST request.

πŸ“… Published: May 24, 2024, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-35395 -

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

πŸ“… Published: May 24, 2024, 3:59 p.m. πŸ”„ Last Modified: April 3, 2025, 3:45 p.m.
Total resulsts: 349182
Page 9672 of 34,919
Β« previous page Β» next page
Filters