|
251661
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48710
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251662
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47556
|
2024-10-17 02:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251663
|
6.1 |
MEDIUM
Local
|
qualcomm
|
wsa8835_firmware wsa8830_firmware wcd9380_firmware snapdragon_8\+_gen_2_mobile_platform_firmware snapdragon_8\+_gen_1_mobile_platform_firmware snapdragon_8_gen_3_mobile_platform_firmwa…
|
Information disclosure while sending implicit broadcast containing APP launch information.
|
CWE-863
Incorrect Authorization
|
CVE-2024-38425
|
2024-10-17 02:34 |
2024-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251664
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47557
|
2024-10-17 02:33 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251665
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
ex3700_firmware ex6100_firmware ex6120_firmware
|
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
|
CWE-77
Command Injection
|
CVE-2024-35519
|
2024-10-17 02:17 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251666
|
- |
|
-
|
-
|
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier version…
|
-
|
CVE-2024-35584
|
2024-10-17 02:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251667
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
r7000_firmware
|
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
|
CWE-77
Command Injection
|
CVE-2024-35520
|
2024-10-17 02:14 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251668
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
ex6120_firmware
|
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
|
CWE-77
Command Injection
|
CVE-2024-35518
|
2024-10-17 02:13 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251669
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashbo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-8977
|
2024-10-17 02:10 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251670
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated a…
|
NVD-CWE-noinfo
|
CVE-2024-9596
|
2024-10-17 02:00 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|