|
306381
|
- |
|
-
|
-
|
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allow…
|
-
|
CVE-2024-48631
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306382
|
- |
|
-
|
-
|
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allow…
|
-
|
CVE-2024-48630
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306383
|
- |
|
-
|
-
|
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerab…
|
-
|
CVE-2024-48629
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306384
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in easy.Jobs EasyJobs allows Reflected XSS.This issue affects EasyJobs: from n/a through 2.4.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43997
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306385
|
- |
|
-
|
-
|
The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-49399
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306386
|
- |
|
-
|
-
|
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-49398
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306387
|
- |
|
-
|
-
|
The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.
|
CWE-79
Cross-site Scripting
|
CVE-2024-49397
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306388
|
- |
|
-
|
-
|
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-49396
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306389
|
- |
|
-
|
-
|
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root
|
-
|
CVE-2024-48192
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306390
|
- |
|
-
|
-
|
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9414
|
2024-10-18 21:52 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|