7.5

CVSS3.1

CVE-2024-33605 -

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

5.9

CVSS3.1

CVE-2024-32151 -

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [Refere…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

5.9

CVSS3.1

CVE-2024-29978 -

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [Refere…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

5.9

CVSS3.1

CVE-2024-29146 -

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [Refere…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

5.9

CVSS3.1

CVE-2024-28955 -

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provid…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

9

CVSS3.1

CVE-2024-28038 -

The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

6.1

CVSS3.1

CVE-2024-11202 - Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Short…

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec…

📅 Published: Nov. 26, 2024, 7:31 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.

7.2

CVSS3.1

CVE-2024-9504 - Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scriptin…

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in…

📅 Published: Nov. 26, 2024, 7:31 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

3.8

CVSS3.1

CVE-2024-8160 -

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This flaw can only be exploited after authenticating…

📅 Published: Nov. 26, 2024, 7:27 a.m. 🔄 Last Modified: Jan. 22, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2024-8772 -

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited afte…

📅 Published: Nov. 26, 2024, 7:24 a.m. 🔄 Last Modified: March 28, 2025, 7:16 a.m.
Total resulsts: 343746
Page 7160 of 34,375
« previous page » next page
Filters