Latest CVE Feed
-
7.2
HIGHCVE-2024-7728
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.... Read more
Affected Products :- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
6.5
MEDIUMCVE-2024-42368
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. The bearertokenauth extension's server authenticator perf... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.5
HIGHCVE-2024-6618
In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
5.4
MEDIUMCVE-2024-6079
A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a ... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
7.4
HIGHCVE-2024-37015
An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-mid... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.7
HIGHCVE-2024-7113
If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.5
HIGHCVE-2024-6619
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
6.9
MEDIUMCVE-2024-7567
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 14, 2024
-
8.5
HIGHCVE-2024-38206
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.... Read more
Affected Products : copilot_studio- Published: Aug. 06, 2024
- Modified: Aug. 14, 2024
-
8.2
HIGHCVE-2024-38166
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.... Read more
Affected Products : dynamics_crm_service_portal_web_resource- Published: Aug. 06, 2024
- Modified: Aug. 14, 2024
-
8.8
HIGHCVE-2024-39091
An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.9
CRITICALCVE-2024-6684
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass.This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that th... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42742
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42623
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42743
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42631
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42627
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42543
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42737
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
9.1
CRITICAL- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024