6.1

CVSS3.1

CVE-2024-48535 -

A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:43 p.m.

9.1

CVSS3.1

CVE-2024-33439 -

An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-45511 -

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder …

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 9:16 p.m.

9.1

CVSS3.1

CVE-2024-29292 -

Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-52771 -

DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 2:23 p.m.

3.5

CVSS3.1

CVE-2024-52757 -

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, 5:15 p.m.

3.5

CVSS3.1

CVE-2024-52755 -

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 22, 2024, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-52765 -

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2024-51162 -

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes…

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-48982 -

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case. Supplying a length less than…

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2024, 9:15 p.m.
Total resulsts: 346554
Page 7521 of 34,656
Β« previous page Β» next page
Filters