8.8

CVSS3.1

CVE-2024-32350 -

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.

πŸ“… Published: May 14, 2024, 3:55 p.m. πŸ”„ Last Modified: April 4, 2025, 2:28 p.m.

6

CVSS3.1

CVE-2024-32349 -

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

πŸ“… Published: May 14, 2024, 3:52 p.m. πŸ”„ Last Modified: April 4, 2025, 2:28 p.m.

5.3

CVSS3.1

CVE-2024-34717 - Anonymous PrestaShop customer can download other customers' invoices

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.

πŸ“… Published: May 14, 2024, 3:47 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 4:04 p.m.

9.7

CVSS3.1

CVE-2024-34716 - PrestaShop vulnerable to XSS via customer contact form in FO, through file upload

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled throu…

πŸ“… Published: May 14, 2024, 3:45 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 4:06 p.m.

6.5

CVSS3.1

CVE-2024-34191 -

htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.

πŸ“… Published: May 14, 2024, 3:31 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 5:59 p.m.

7.5

CVSS3.1

CVE-2024-34950 -

D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.

πŸ“… Published: May 14, 2024, 3:27 p.m. πŸ”„ Last Modified: May 21, 2025, 1:05 p.m.

5.4

CVSS3.1

CVE-2024-34243 -

Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

πŸ“… Published: May 14, 2024, 3:19 p.m. πŸ”„ Last Modified: June 13, 2025, 1:12 p.m.

5.3

CVSS3.1

CVE-2024-34914 -

php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.

πŸ“… Published: May 14, 2024, 3:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-1486 - Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

πŸ“… Published: May 14, 2024, 3:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-1598 - Potential buffer overflow when handling UEFI variables

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreβ„’ for Intel Gemini Lake.This issue affects: SecureCoreβ„’ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.

πŸ“… Published: May 14, 2024, 2:56 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 9:20 p.m.
Total resulsts: 349182
Page 9870 of 34,919
Β« previous page Β» next page
Filters