Latest CVE Feed
-
4.3
MEDIUMCVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-57680
An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-57679
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57678
An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-57677
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57676
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-52594
Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advis... Read more
Affected Products : gomatrixserverlib- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-20072
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
4.6
MEDIUMCVE-2024-57776
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57775
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-57774
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
-
4.8
MEDIUMCVE-2024-57773
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57772
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57771
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57770
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-57769
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57768
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
0.0
NONECVE-2024-50633
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentiona... Read more
Affected Products : indico- Published: Jan. 16, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization