9.8

CVSS3.1

CVE-2024-50667 -

The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 6:21 p.m.

7.5

CVSS3.1

CVE-2024-52532 - libsoup: infinite loop while reading websocket data

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

6.1

CVSS3.1

CVE-2024-51213 -

Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50989 -

A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 5:57 p.m.

5.5

CVSS3.1

CVE-2024-11079 - Ansible-core: unsafe tagging bypass via hostvars object in ansible-core

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-46965 -

The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-44546 -

Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 6:51 p.m.

7.5

CVSS3.1

CVE-2024-52530 - libsoup: HTTP request smuggling via stripping null bytes from the ends of header names

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

9.8

CVSS3.1

CVE-2024-36061 -

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 4:12 p.m.

6.1

CVSS3.1

CVE-2024-50990 -

A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.

๐Ÿ“… Published: Nov. 11, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 5:34 p.m.
Total resulsts: 345209
Page 7555 of 34,521
ยซ previous page ยป next page
Filters