Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-35557 | 2024-07-03 | N/A | 5.5 MEDIUM | ||
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close. | |||||
| CVE-2024-35555 | 2024-07-03 | N/A | 6.3 MEDIUM | ||
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40. | |||||
| CVE-2024-35554 | 2024-07-03 | N/A | N/A | ||
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN. | |||||
| CVE-2024-35551 | 2024-07-03 | N/A | N/A | ||
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add. | |||||
| CVE-2024-35511 | 2024-07-03 | N/A | 4.7 MEDIUM | ||
| phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php. | |||||
| CVE-2024-35510 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-35475 | 2024-07-03 | N/A | 6.4 MEDIUM | ||
| A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands. | |||||
| CVE-2024-35430 | 2024-07-03 | N/A | 8.1 HIGH | ||
| In ZKTeco ZKBio CVSecurity v6.1.1 an authenticated user can bypass password checks while exporting data from the application. | |||||
| CVE-2024-35403 | 2024-07-03 | N/A | 2.7 LOW | ||
| TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules | |||||
| CVE-2024-35398 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules. | |||||
| CVE-2024-35396 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root. | |||||
| CVE-2024-35395 | 2024-07-03 | N/A | 8.8 HIGH | ||
| TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root. | |||||
| CVE-2024-35388 | 2024-07-03 | N/A | 8.8 HIGH | ||
| TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode | |||||
| CVE-2024-35387 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth. | |||||
| CVE-2024-35385 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file. | |||||
| CVE-2024-35361 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights. | |||||
| CVE-2024-35357 | 2024-07-03 | N/A | 5.3 MEDIUM | ||
| A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection. | |||||
| CVE-2024-35356 | 2024-07-03 | N/A | 6.3 MEDIUM | ||
| A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection. | |||||
| CVE-2024-35353 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization. | |||||
| CVE-2024-35352 | 2024-07-03 | N/A | 6.1 MEDIUM | ||
| A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename results in cross-site scripting. | |||||
