Latest CVE Feed
-
6.8
MEDIUMCVE-2024-10709
The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform S... Read more
Affected Products : yadisk_files- Published: Nov. 25, 2024
- Modified: May. 15, 2025
-
7.2
HIGHCVE-2024-11656
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
7.2
HIGHCVE-2024-11655
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to com... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
7.2
HIGHCVE-2024-11654
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to comm... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
7.2
HIGHCVE-2024-11653
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
5.0
MEDIUMCVE-2024-11483
A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth... Read more
Affected Products :- Published: Nov. 25, 2024
- Modified: Dec. 18, 2024
-
5.4
MEDIUMCVE-2024-53930
WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.... Read more
Affected Products :- Published: Nov. 25, 2024
- Modified: Nov. 26, 2024
-
7.2
HIGHCVE-2024-11652
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
7.2
HIGHCVE-2024-11651
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_schedule_day_em_5... Read more
Affected Products : enh1350ext_firmware enh1350ext ens500-ac_firmware eens500-ac ens620ext_firmware ens620ext ens500-ac- Published: Nov. 25, 2024
- Modified: Feb. 12, 2025
-
7.5
HIGHCVE-2024-11650
A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploi... Read more
Affected Products : i9_firmware- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-11649
A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql in... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-11648
A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/add-customer.php. The manipulation of the argument name leads to sql injection. It is possi... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-11647
A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. The manipulation of the argument viewid ... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
7.5
HIGHCVE-2024-53916
In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileged tenant is able to change (add and clear) tags on netw... Read more
Affected Products : smart_vms- Published: Nov. 25, 2024
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2024-11646
A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-services.php. The manipulation of the argument sername leads to sql ... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-11666
Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated users su... Read more
- Published: Nov. 24, 2024
- Modified: Dec. 03, 2024
-
8.8
HIGHCVE-2024-11665
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.... Read more
- Published: Nov. 24, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-53915
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2024-53914
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2024-53913
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.... Read more
Affected Products : enterprise_vault- Published: Nov. 24, 2024
- Modified: Nov. 29, 2024