6.6

CVSS3.1

CVE-2023-31493 -

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 1:55 p.m.

9.8

CVSS3.1

CVE-2024-49195 -

Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 6:01 p.m.

6.5

CVSS3.1

CVE-2024-48713 -

In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:27 p.m.

4.3

CVSS3.1

CVE-2024-48783 -

An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2024, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-48283 -

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: April 4, 2025, 2:36 p.m.

9.8

CVSS3.1

CVE-2024-48781 -

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 16, 2024, 7:35 p.m.

6.5

CVSS3.1

CVE-2024-48710 -

In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 8:27 p.m.

8.1

CVSS3.1

CVE-2024-41311 -

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: March 24, 2025, 2:41 p.m.

5.3

CVSS3.1

CVE-2024-48624 -

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 6:02 p.m.

7.6

CVSS3.1

CVE-2024-48279 -

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

๐Ÿ“… Published: Oct. 15, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 5:19 p.m.
Total resulsts: 342654
Page 7642 of 34,266
ยซ previous page ยป next page
Filters