Show filters
842 Total Results
Displaying 81-90 of 842
Sort by:
Attacker Value
Unknown

CVE-2024-43312

Disclosure Date: November 01, 2024 (last updated November 13, 2024)
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.1.9.
Attacker Value
Unknown

CVE-2024-43223

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
0
Attacker Value
Unknown

CVE-2024-38707

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4.
0
Attacker Value
Unknown

CVE-2024-33700

Disclosure Date: October 30, 2024 (last updated November 09, 2024)
The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to cause a denial of service through a series of malformed FTP commands. This can lead to device reboots and service disruption.
Attacker Value
Unknown

CVE-2024-33699

Disclosure Date: October 30, 2024 (last updated November 09, 2024)
The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.
Attacker Value
Unknown

CVE-2024-33626

Disclosure Date: October 30, 2024 (last updated November 14, 2024)
The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.
Attacker Value
Unknown

CVE-2024-33623

Disclosure Date: October 30, 2024 (last updated November 14, 2024)
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2024-33603

Disclosure Date: October 30, 2024 (last updated November 14, 2024)
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.
Attacker Value
Unknown

CVE-2024-32946

Disclosure Date: October 30, 2024 (last updated November 14, 2024)
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.
Attacker Value
Unknown

CVE-2024-31152

Disclosure Date: October 30, 2024 (last updated November 14, 2024)
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lead to network service interruptions.