|
250351
|
6.1 |
MEDIUM
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability.
Accessing a crafted URL which points to an affected prod…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47801
|
2024-11-6 04:34 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250352
|
8.8 |
HIGH
Network
|
draytek
|
vigor3900_firmware
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
|
CWE-78
OS Command
|
CVE-2024-51248
|
2024-11-6 04:28 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250353
|
8.8 |
HIGH
Network
|
draytek
|
vigor3900_firmware
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
|
CWE-78
OS Command
|
CVE-2024-51247
|
2024-11-6 04:28 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250354
|
8.8 |
HIGH
Network
|
draytek
|
vigor3900_firmware
|
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
|
CWE-78
OS Command
|
CVE-2024-51245
|
2024-11-6 04:28 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250355
|
8.8 |
HIGH
Network
|
draytek
|
vigor3900_firmware
|
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
|
CWE-78
OS Command
|
CVE-2024-51244
|
2024-11-6 04:28 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250356
|
- |
|
-
|
-
|
localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the paylo…
|
-
|
CVE-2024-48057
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250357
|
- |
|
-
|
-
|
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.…
|
-
|
CVE-2024-30619
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250358
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' pa…
|
-
|
CVE-2024-30618
|
2024-11-6 03:35 |
2024-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250359
|
- |
|
-
|
-
|
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
|
-
|
CVE-2024-48352
|
2024-11-6 03:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250360
|
- |
|
-
|
-
|
Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system co…
|
-
|
CVE-2024-51399
|
2024-11-6 03:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|