|
248661
|
5.4 |
MEDIUM
Network
|
siemens
|
ozw672_firmware ozw772_firmware
|
A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks…
|
CWE-79
Cross-site Scripting
|
CVE-2024-36140
|
2024-11-16 07:53 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248662
|
4.8 |
MEDIUM
Network
|
publiccms
|
publiccms
|
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The ma…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11175
|
2024-11-16 07:50 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248663
|
7.8 |
HIGH
Local
|
siemens
|
spectrum_power_7
|
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an authenticated local attacker to esca…
|
NVD-CWE-noinfo
|
CVE-2024-29119
|
2024-11-16 07:50 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248664
|
7.2 |
HIGH
Network
|
timgeyssens
|
ui-o-matic
|
A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. T…
|
CWE-89
SQL Injection
|
CVE-2024-11124
|
2024-11-16 07:47 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248665
|
- |
|
-
|
-
|
Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.
|
-
|
CVE-2021-27703
|
2024-11-16 07:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248666
|
- |
|
-
|
-
|
Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.
|
-
|
CVE-2021-27702
|
2024-11-16 07:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248667
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
udf: fix uninit-value use in udf_get_fileshortad
Check for overflow when computing alen in udf_current_aext to mitigate
later uni…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-50143
|
2024-11-16 07:22 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248668
|
- |
|
-
|
-
|
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the…
|
-
|
CVE-2021-37577
|
2024-11-16 06:35 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248669
|
- |
|
-
|
-
|
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:
?Product
Affected Versions
LoadMaster
Fro…
|
CWE-20
Improper Input Validation
|
CVE-2024-8755
|
2024-11-16 06:15 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248670
|
5.5 |
MEDIUM
Local
|
cysoft168
|
super_easy_enterprise_management_system
|
An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark.
|
CWE-22
Path Traversal
|
CVE-2024-42680
|
2024-11-16 06:15 |
2024-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|