9.8

CVSS3.1

CVE-2024-35396 -

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

๐Ÿ“… Published: May 24, 2024, 3:54 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 3:45 p.m.

4.9

CVSS3.1

CVE-2024-33470 -

An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

๐Ÿ“… Published: May 24, 2024, 3:03 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-22588 -

Kwik commit 745fd4e2 does not discard unused encryption keys.

๐Ÿ“… Published: May 24, 2024, 2:55 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-33809 -

PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.

๐Ÿ“… Published: May 24, 2024, 2:53 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 6:41 p.m.

8.6

CVSS3.1

CVE-2024-35340 -

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

๐Ÿ“… Published: May 24, 2024, 2:50 p.m. ๐Ÿ”„ Last Modified: April 9, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-35618 -

PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.

๐Ÿ“… Published: May 24, 2024, 2:50 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 5:30 p.m.

9.8

CVSS3.1

CVE-2024-35339 -

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

๐Ÿ“… Published: May 24, 2024, 2:49 p.m. ๐Ÿ”„ Last Modified: April 9, 2025, 2:14 p.m.

9.6

CVSS3.1

CVE-2024-35592 -

An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code via uploading a crafted PDF file.

๐Ÿ“… Published: May 24, 2024, 2:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-35591 -

An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

๐Ÿ“… Published: May 24, 2024, 1:50 p.m. ๐Ÿ”„ Last Modified: Sept. 30, 2025, 6:34 p.m.

4.3

CVSS3.1

CVE-2024-5273 -

Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by eโ€ฆ

๐Ÿ“… Published: May 24, 2024, 1:46 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 3:34 p.m.
Total resulsts: 349182
Page 9673 of 34,919
ยซ previous page ยป next page
Filters