Latest CVE Feed
-
7.5
HIGHCVE-2024-52802
RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum header length check for `dhcpv6_opt_t` after processin... Read more
Affected Products : riot- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.1
MEDIUMCVE-2024-52793
The Deno Standard Library provides APIs for Deno and the Web. Prior to version 1.0.11, `http/file-server`'s `serveDir` with `showDirListing: true` option is vulnerable to cross-site scripting when the attacker is a user who can control file names in the s... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.8
CRITICALCVE-2024-52723
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.... Read more
- Published: Nov. 22, 2024
- Modified: Mar. 13, 2025
-
6.7
MEDIUMCVE-2024-51074
Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. NOTE: this is ... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Jan. 13, 2025
-
6.7
MEDIUMCVE-2024-51073
An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster and CAN bus. NOTE: this is disputed by the Supplier because the findings came from a ... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Jan. 13, 2025
-
5.3
MEDIUMCVE-2024-51072
An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealisti... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Jan. 10, 2025
-
5.4
MEDIUMCVE-2024-50965
Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2024-50401
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2024-50400
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2024-50399
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2024-50398
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
7.7
HIGHCVE-2024-50397
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory.... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
7.7
HIGHCVE-2024-50396
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the ... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
6.9
MEDIUMCVE-2024-50395
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the fo... Read more
Affected Products : media_streaming_add-on- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
8.7
HIGHCVE-2024-48862
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have alre... Read more
Affected Products : qulog_center- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
7.3
HIGHCVE-2024-48861
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRout... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.5
CRITICALCVE-2024-48860
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
7.9
HIGHCVE-2024-38647
An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following v... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
8.4
HIGHCVE-2024-38646
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resour... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.4
CRITICALCVE-2024-38645
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following ... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024