6.8

CVSS3.1

CVE-2023-33548 -

Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-4840 - Rhosp-director: cleartext passwords exposed in logs

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-33112 -

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 1:02 p.m.

5.4

CVSS3.1

CVE-2024-33111 -

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 1:02 p.m.

9.8

CVSS3.1

CVE-2024-34249 -

wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 6:46 p.m.

7.1

CVSS3.1

CVE-2024-28725 -

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: June 10, 2025, 7:42 p.m.

9.1

CVSS3.1

CVE-2024-33294 -

An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-34471 -

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete โ€ฆ

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 5:13 p.m.

5.4

CVSS3.1

CVE-2024-34064 - Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts kโ€ฆ

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

8.2

CVSS3.1

CVE-2024-33753 -

Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

๐Ÿ“… Published: May 6, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9977 of 34,919
ยซ previous page ยป next page
Filters