Latest CVE Feed
-
5.7
MEDIUMCVE-2024-51002
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
5.7
MEDIUMCVE-2024-51001
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-51000
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-50999
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-50998
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Servic... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-50997
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 01, 2025
-
5.7
MEDIUMCVE-2024-50996
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a cr... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 07, 2025
-
5.7
MEDIUMCVE-2024-50995
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
5.7
MEDIUMCVE-2024-50994
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities allow attackers to ca... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
8.0
HIGHCVE-2024-50993
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-10845
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be ... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10844
A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the a... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2023-29115
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.7
MEDIUMCVE-2023-29114
System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: • Wi-Fi access point credentials to which the EV charger can connect. • APN web addre... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 05, 2024
-
5.1
MEDIUMCVE-2024-10842
A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Us... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-10841
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql inj... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
4.3
MEDIUMCVE-2024-10329
The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, w... Read more
Affected Products : ultimate_bootstrap_elements_for_elementor- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.9
HIGHCVE-2024-7059
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.... Read more
Affected Products : security_center- Published: Nov. 05, 2024
- Modified: Nov. 09, 2024
-
5.1
MEDIUMCVE-2024-10840
A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is ... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.3
HIGHCVE-2024-10263
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a va... Read more
Affected Products : tickera- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024