Latest CVE Feed
-
9.8
CRITICALCVE-2024-44341
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-36068
An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.... Read more
Affected Products : cloud_data_management- Published: Aug. 27, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-7720
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.... Read more
Affected Products : security_manager- Published: Aug. 27, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8212
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8214
A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8218
A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remo... Read more
Affected Products : online_quiz_site- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8222
A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation of the argument id leads to sql injection. It is possible to initia... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8225
A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to stack-based buffer overflow. It is poss... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8230
A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer ov... Read more
- Published: Aug. 28, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2023-26321
A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.... Read more
Affected Products : file_manager- Published: Aug. 28, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2023-26324
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.... Read more
Affected Products : getapps- Published: Aug. 28, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-34198
TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTT... Read more
- Published: Aug. 28, 2024
- Modified: Jul. 03, 2025
-
9.8
CRITICALCVE-2024-42905
Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.... Read more
Affected Products :- Published: Aug. 28, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-45435
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.... Read more
Affected Products : chartist- Published: Aug. 29, 2024
- Modified: Sep. 03, 2024
-
9.8
CRITICALCVE-2024-29724
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax... Read more
Affected Products : sportsnet- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-29725
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ap... Read more
Affected Products : sportsnet- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-29726
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ap... Read more
Affected Products : sportsnet- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-29727
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/a... Read more
Affected Products : sportsnet- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-8294
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument FriendlyLink[image] leads to unrestricted upload... Read more
Affected Products : feehicms- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-8296
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument User[avatar] leads to unrestricted upload. The attack may b... Read more
Affected Products : feehicms- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024