Latest CVE Feed
-
9.1
CVSS31CVE-2024-39768
Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request t... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
9.1
CVSS31CVE-2024-39765
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated H... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
9.1
CVSS31CVE-2024-39764
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated H... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
9.1
CVSS31CVE-2024-39763
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated H... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
9.1
CVSS31CVE-2024-39762
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated H... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
10.0
CVSS31CVE-2024-39761
Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP req... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
10.0
CVSS31CVE-2024-39760
Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP req... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
10.0
CVSS31CVE-2024-39759
Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP req... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.5
CVSS31CVE-2024-36504
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN ... Read more
Affected Products : fortios- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
5.5
CVSS31CVE-2024-32115
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.... Read more
Affected Products : fortimanager- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
8.1
CVSS31CVE-2024-23106
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HT... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.4
CVSS31CVE-2024-21758
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protection... Read more
Affected Products : fortiweb- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42250
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42249
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42247
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42246
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42245
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42233
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
6.1
CVSS31CVE-2023-42230
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
-
8.8
CVSS31CVE-2023-37931
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack v... Read more
Affected Products : fortivoice- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025