Latest CVE Feed
-
5.4
MEDIUMCVE-2024-28730
Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 22, 2024
-
9.8
CRITICALCVE-2024-28729
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 22, 2024
-
6.6
MEDIUMCVE-2024-28728
Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via a crafted payload to the WiFi SSID Name field.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.0
HIGHCVE-2024-28726
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.... Read more
Affected Products : dwr-2000m_firmware- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
6.5
MEDIUMCVE-2021-27704
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.... Read more
Affected Products : appspace- Published: Nov. 12, 2024
- Modified: Jun. 27, 2025
-
5.4
MEDIUMCVE-2021-27703
Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 15, 2024
-
7.3
HIGHCVE-2021-27702
Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 15, 2024
-
4.7
MEDIUMCVE-2021-27701
SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF r... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.6
HIGHCVE-2021-27700
SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard and perform actions like modify user, delete user, etc.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-51179
An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establis... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
5.3
MEDIUMCVE-2024-48075
A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2024-11168
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than o... Read more
Affected Products : python- Published: Nov. 12, 2024
- Modified: Apr. 11, 2025
-
8.0
HIGHCVE-2024-51094
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, ... Read more
Affected Products : snipe-it- Published: Nov. 12, 2024
- Modified: May. 22, 2025
-
8.7
HIGHCVE-2024-51093
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permi... Read more
Affected Products : snipe-it- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-49512
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
5.5
MEDIUMCVE-2024-49511
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
5.5
MEDIUMCVE-2024-49510
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49509
InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49508
InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024
-
7.8
HIGHCVE-2024-49507
InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 16, 2024