8.8
CVE-2024-32350 -
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
6
CVE-2024-32349 -
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
5.3
CVE-2024-34717 - Anonymous PrestaShop customer can download other customers' invoices
PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.
9.7
CVE-2024-34716 - PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled throuβ¦
6.5
CVE-2024-34191 -
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.
7.5
CVE-2024-34950 -
D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.
5.4
CVE-2024-34243 -
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
5.3
CVE-2024-34914 -
php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.
7.4
CVE-2024-1486 - Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
7.5
CVE-2024-1598 - Potential buffer overflow when handling UEFI variables
Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreβ’ for Intel Gemini Lake.This issue affects: SecureCoreβ’ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.