9.8

CVSS3.1

CVE-2024-57583 -

Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 4, 2025, 3:15 p.m.

7.8

CVSS3.1

CVE-2024-55511 -

A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentially elevate their privileges via executing a specially crafted executable.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-57771 -

A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 17, 2025, 2:40 a.m.

7.2

CVSS3.1

CVE-2024-57162 -

Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2024-57676 -

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:31 p.m.

7.3

CVSS3.1

CVE-2024-57703 -

Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 2:59 p.m.

9.8

CVSS3.1

CVE-2024-57768 -

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 5:47 p.m.

8.8

CVSS3.1

CVE-2024-57769 -

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 23, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2024-57681 -

An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:31 p.m.

4.8

CVSS3.1

CVE-2024-57774 -

A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 17, 2025, 2:42 a.m.
Total resulsts: 346552
Page 6829 of 34,656
ยซ previous page ยป next page
Filters