|
249141
|
5.4 |
MEDIUM
Network
|
radixiot
|
mango
|
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2024-37844
|
2024-11-6 01:03 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249142
|
5.4 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due …
|
CWE-79
Cross-site Scripting
|
CVE-2024-20387
|
2024-11-6 01:00 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249143
|
8.8 |
HIGH
Network
|
radixiot
|
mangoapi mango
|
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
|
CWE-22
Path Traversal
|
CVE-2024-37847
|
2024-11-6 00:47 |
2024-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249144
|
- |
|
-
|
-
|
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.
|
-
|
CVE-2024-48217
|
2024-11-6 00:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249145
|
8.4 |
HIGH
Local
|
cisco
|
firepower_threat_defense
|
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system usin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-20412
|
2024-11-6 00:03 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249146
|
5.8 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense
|
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy.
This …
|
NVD-CWE-noinfo
|
CVE-2024-20431
|
2024-11-5 23:47 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249147
|
8.8 |
HIGH
Network
|
tenda
|
ac15_firmware
|
A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argumen…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-10662
|
2024-11-5 23:30 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249148
|
8.8 |
HIGH
Network
|
tenda
|
ac15_firmware
|
A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argumen…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-10661
|
2024-11-5 23:30 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249149
|
- |
|
-
|
-
|
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is…
|
CWE-89
SQL Injection
|
CVE-2024-51482
|
2024-11-5 23:15 |
2024-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249150
|
8.8 |
HIGH
Network
|
esafenet
|
cdg
|
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelo…
|
CWE-89
SQL Injection
|
CVE-2024-9560
|
2024-11-5 22:05 |
2024-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|