Latest CVE Feed
-
8.0
HIGHCVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
8.0
HIGHCVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-50531
Unrestricted Upload of File with Dangerous Type vulnerability in David F. Carr RSVPMaker for Toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through 6.2.4.... Read more
Affected Products : rsvpmaker- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50530
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through 1.7.... Read more
Affected Products : stars_smtp_mailer- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50529
Unrestricted Upload of File with Dangerous Type vulnerability in Rudra Innnovative Software Training – Courses allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through 2.0.1.... Read more
Affected Products : training_-_courses- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-50528
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50527
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50526
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more
Affected Products : multi_purpose_mail_form- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50525
Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into... Read more
Affected Products : helloprint- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50523
Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through 1.7.3.... Read more
Affected Products : all_post_contact_form- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-45164
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality ... Read more
Affected Products : secure_internet_access_enterprise_threatavert- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.9
MEDIUMCVE-2024-9147
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.2.1.... Read more
Affected Products : pospratik- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.3
CRITICALCVE-2024-51561
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the se... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-51560
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API reques... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-51559
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicio... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 22, 2024
-
9.8
CRITICALCVE-2024-51558
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, M... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-51557
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead t... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-51556
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 22, 2024
-
8.8
HIGHCVE-2024-36485
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.... Read more
Affected Products : manageengine_adaudit_plus- Published: Nov. 04, 2024
- Modified: Nov. 07, 2024
-
4.6
MEDIUMCVE-2024-10523
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024