Latest CVE Feed
-
6.9
MEDIUMCVE-2024-7567
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
6.5
MEDIUMCVE-2024-42368
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. The bearertokenauth extension's server authenticator perf... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.5
HIGHCVE-2024-38206
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.... Read more
Affected Products : copilot_studio- Published: Aug. 06, 2024
- Modified: Aug. 14, 2024
-
8.2
HIGHCVE-2024-38166
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.... Read more
Affected Products : dynamics_crm_service_portal_web_resource- Published: Aug. 06, 2024
- Modified: Aug. 14, 2024
-
8.8
HIGHCVE-2024-39091
An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.9
CRITICALCVE-2024-6684
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass.This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that th... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42742
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42623
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42743
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42631
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42627
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42543
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42737
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
9.1
CRITICAL- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42625
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42747
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42741
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.1
MEDIUMCVE-2024-21550
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSock... Read more
Affected Products : steve- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2024-27442
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privile... Read more
Affected Products : collaboration- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-38530
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's ... Read more
Affected Products : openeclass- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024