Latest CVE Feed
-
8.8
HIGHCVE-2024-42625
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42747
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42741
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.1
MEDIUMCVE-2024-21550
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSock... Read more
Affected Products : steve- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2024-27442
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privile... Read more
Affected Products : collaboration- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-38530
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's ... Read more
Affected Products : openeclass- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
10.0
CRITICALCVE-2024-6917
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue affects Veribase Order Management: before v4.010.2.... Read more
Affected Products : order_management- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2023-7249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.... Read more
Affected Products : directory_services- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42745
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42748
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42547
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42629
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-7616
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The v... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.6
HIGHCVE-2024-7408
This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42632
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42630
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42626
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42545
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42520
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.3
MEDIUMCVE-2024-41240
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter.... Read more
Affected Products : responsive_school_management_system- Published: Aug. 07, 2024
- Modified: Aug. 13, 2024