7.5

CVSS3.1

CVE-2024-11981 - Billion Electric router - Authentication Bypass

Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

πŸ“… Published: Nov. 29, 2024, 6:21 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 2:31 p.m.

8.6

CVSS3.1

CVE-2024-11980 - Billion Electric router - Missing Authentication

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

πŸ“… Published: Nov. 29, 2024, 6:03 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 2:40 p.m.

5.4

CVSS3.1

CVE-2024-10980 - Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow u…

πŸ“… Published: Nov. 29, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 12:03 a.m.

4.8

CVSS3.1

CVE-2024-10704 - Photo Gallery by 10Web < 1.8.31 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Nov. 29, 2024, 6 a.m. πŸ”„ Last Modified: May 7, 2025, 12:07 a.m.

3.1

CVSS3.0

CVE-2024-53701 -

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security…

πŸ“… Published: Nov. 29, 2024, 5:39 a.m. πŸ”„ Last Modified: Dec. 3, 2024, 2:09 p.m.

9.8

CVSS3.1

CVE-2024-11979 - Interinfo DreamMaker - Unrestricted File Upload through Path Traversal

DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

πŸ“… Published: Nov. 29, 2024, 2:12 a.m. πŸ”„ Last Modified: Dec. 3, 2024, 6:05 a.m.

7.5

CVSS3.1

CVE-2024-11978 - Interinfo DreamMaker - Arbitrary File Reading through Path Traversal

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

πŸ“… Published: Nov. 29, 2024, 2:03 a.m. πŸ”„ Last Modified: Dec. 3, 2024, 6:06 a.m.

6.1

CVSS3.1

CVE-2024-36624 -

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 1:49 p.m.

7.5

CVSS3.1

CVE-2024-35371 -

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included i…

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: Dec. 2, 2024, 5:15 p.m.

5.5

CVSS3.1

CVE-2024-35369 -

In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in unde…

πŸ“… Published: Nov. 29, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 4:06 p.m.
Total resulsts: 343975
Page 7150 of 34,398
Β« previous page Β» next page
Filters