|
256371
|
9.8 |
CRITICAL
Network
|
totolink
|
lr350_firmware
|
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-…
|
NVD-CWE-noinfo
|
CVE-2024-42967
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256372
|
9.8 |
CRITICAL
Network
|
tenda
|
fh1201_firmware
|
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
|
NVD-CWE-noinfo
|
CVE-2024-42947
|
2024-09-7 02:35 |
2024-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256373
|
7.8 |
HIGH
Local
|
cysoft168
|
super_easy_enterprise_management_system
|
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
|
CWE-89
SQL Injection
|
CVE-2024-42679
|
2024-09-7 02:35 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256374
|
4.8 |
MEDIUM
Network
|
micro.company
|
collect.chat
|
The Chatbot for WordPress by Collect.chat ?? WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Sit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6498
|
2024-09-7 02:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256375
|
8.6 |
HIGH
Network
|
rocket.chat
|
rocket.chat
|
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-39713
|
2024-09-7 02:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256376
|
- |
|
-
|
-
|
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive informati…
|
-
|
CVE-2024-6477
|
2024-09-7 02:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256377
|
7.2 |
HIGH
Network
|
teamt5
|
threatsonar_anti-ransomware
|
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, w…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7694
|
2024-09-7 02:24 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256378
|
5.4 |
MEDIUM
Network
|
wpextended
|
wp_extended
|
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8123
|
2024-09-7 02:20 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256379
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-20488
|
2024-09-7 02:18 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256380
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-45294. Reason: This candidate is a duplicate of CVE-2024-45294. Notes: All CVE users should reference CVE-2024-452…
|
-
|
CVE-2024-45295
|
2024-09-7 02:15 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|