9.1

CVSS3.1

CVE-2024-53553 -

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 29, 2025, 3:21 p.m.

8.1

CVSS3.1

CVE-2024-46450 -

Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: July 7, 2025, 4:40 p.m.

9.8

CVSS3.1

CVE-2024-57582 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: March 22, 2025, 2:15 p.m.

5.7

CVSS3.1

CVE-2024-57578 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 2:53 p.m.

4.8

CVSS3.1

CVE-2024-57773 -

A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 17, 2025, 2:40 a.m.

3.5

CVSS3.1

CVE-2024-57159 -

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2025, 8:09 p.m.

4.3

CVSS3.1

CVE-2024-48460 -

An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-57684 -

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:31 p.m.

5.3

CVSS3.1

CVE-2024-57680 -

An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:31 p.m.

8.8

CVSS3.1

CVE-2024-57770 -

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.

๐Ÿ“… Published: Jan. 16, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 23, 2025, 5:15 p.m.
Total resulsts: 346547
Page 6830 of 34,655
ยซ previous page ยป next page
Filters