Latest CVE Feed
-
8.8
HIGHCVE-2024-42623
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42743
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42631
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42627
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42543
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42737
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
9.1
CRITICAL- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42625
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42747
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42741
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.1
MEDIUMCVE-2024-21550
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSock... Read more
Affected Products : steve- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2024-27442
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privile... Read more
Affected Products : collaboration- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-38530
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's ... Read more
Affected Products : openeclass- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
10.0
CRITICALCVE-2024-6917
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue affects Veribase Order Management: before v4.010.2.... Read more
Affected Products : order_management- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2023-7249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.... Read more
Affected Products : directory_services- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42745
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42748
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42547
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.8
HIGHCVE-2024-42629
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.... Read more
Affected Products : frogcms- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-7616
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The v... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024