|
313741
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48714
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313742
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48713
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313743
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48712
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313744
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48710
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313745
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47556
|
2024-10-17 02:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313746
|
6.1 |
MEDIUM
Local
|
qualcomm
|
wsa8835_firmware wsa8830_firmware wcd9380_firmware snapdragon_8\+_gen_2_mobile_platform_firmware snapdragon_8\+_gen_1_mobile_platform_firmware snapdragon_8_gen_3_mobile_platform_firmwa…
|
Information disclosure while sending implicit broadcast containing APP launch information.
|
CWE-863
Incorrect Authorization
|
CVE-2024-38425
|
2024-10-17 02:34 |
2024-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313747
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47557
|
2024-10-17 02:33 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313748
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
ex3700_firmware ex6100_firmware ex6120_firmware
|
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
|
CWE-77
Command Injection
|
CVE-2024-35519
|
2024-10-17 02:17 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313749
|
- |
|
-
|
-
|
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier version…
|
-
|
CVE-2024-35584
|
2024-10-17 02:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313750
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
r7000_firmware
|
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
|
CWE-77
Command Injection
|
CVE-2024-35520
|
2024-10-17 02:14 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|