Show filters
329,699 Total Results
Displaying 2,761-2,770 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-46313

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.
0
Attacker Value
Unknown

CVE-2024-46293

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
0
Attacker Value
Unknown

CVE-2024-46280

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.
0
Attacker Value
Unknown

CVE-2024-45792

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.
0
Attacker Value
Unknown

CVE-2024-6051

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.
0
Attacker Value
Unknown

CVE-2024-47641

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloperr Confetti Fall Animation allows Stored XSS.This issue affects Confetti Fall Animation: from n/a through 1.3.0.
0
Attacker Value
Unknown

CVE-2024-45920

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.
0
Attacker Value
Unknown

CVE-2024-45772

Disclosure Date: September 30, 2024 (last updated October 05, 2024)
Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected. Users are recommended to upgrade to version 9.12.0, which fixes the issue. Java serialization filters (such as -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.
Attacker Value
Unknown

CVE-2024-9329

Disclosure Date: September 30, 2024 (last updated October 08, 2024)
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Attacker Value
Unknown

CVE-2024-8459

Disclosure Date: September 30, 2024 (last updated October 05, 2024)
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.