Latest CVE Feed
-
8.0
HIGHCVE-2024-45890
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45889
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45888
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45887
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45885
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45884
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45882
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
7.6
HIGHCVE-2024-51672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more
Affected Products : betterlinks- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2024-51665
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.... Read more
Affected Products : magical_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51582
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.... Read more
Affected Products : wp_hotel_booking- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.5
HIGHCVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.... Read more
Affected Products : appsmith- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
8.0
HIGHCVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-50531
Unrestricted Upload of File with Dangerous Type vulnerability in David F. Carr RSVPMaker for Toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through 6.2.4.... Read more
Affected Products : rsvpmaker- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50530
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through 1.7.... Read more
Affected Products : stars_smtp_mailer- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50529
Unrestricted Upload of File with Dangerous Type vulnerability in Rudra Innnovative Software Training – Courses allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through 2.0.1.... Read more
Affected Products : training_-_courses- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-50528
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50527
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024