Latest CVE Feed
-
9.8
CRITICALCVE-2024-9921
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.... Read more
Affected Products : team\+_pro- Published: Oct. 14, 2024
- Modified: Oct. 24, 2024
-
9.8
CRITICALCVE-2024-7099
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete... Read more
- Published: Oct. 13, 2024
- Modified: Jul. 30, 2025
-
7.2
HIGHCVE-2024-9918
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the argument sql leads to sql injection. The attack can be in... Read more
Affected Products : usualtoolcms- Published: Oct. 13, 2024
- Modified: Oct. 19, 2024
-
6.5
MEDIUMCVE-2024-9917
A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible... Read more
Affected Products : usualtoolcms- Published: Oct. 13, 2024
- Modified: Oct. 19, 2024
-
8.5
HIGHCVE-2024-8070
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary... Read more
Affected Products :- Published: Oct. 13, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9916
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. Th... Read more
Affected Products : usualtoolcms- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9915
A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The manipulation of the argument curTime leads to buffer overflow. The attack ... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9914
A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of the argument curTime leads to buffer overflow. It is possib... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9913
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument curTime leads to buffer overflow. The attack may be initia... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9912
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. The attack can be... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9911
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. It is possible to initi... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9910
A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack may ... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9909
A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file /goform/formSetMuti. The manipulation of the argument curTime leads to buffer overflow. The attack... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
7.1
HIGHCVE-2024-6959
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process eac... Read more
- Published: Oct. 13, 2024
- Modified: Nov. 03, 2024
-
8.8
HIGHCVE-2024-9908
A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument curTime leads to buffer overflow. The exploit has bee... Read more
- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
6.3
MEDIUMCVE-2024-9907
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation leads to weak passwo... Read more
Affected Products :- Published: Oct. 13, 2024
- Modified: Oct. 15, 2024
-
5.4
MEDIUMCVE-2024-9906
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument Code leads to cross site sc... Read more
Affected Products : online_eyewear_shop- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-9905
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument id leads to sq... Read more
Affected Products : online_eyewear_shop- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
7.2
HIGHCVE-2024-9904
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted uplo... Read more
- Published: Oct. 13, 2024
- Modified: Jul. 30, 2025
-
7.2
HIGHCVE-2024-9903
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possi... Read more
- Published: Oct. 12, 2024
- Modified: Jul. 30, 2025