Search Results (372208 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30639 1 Tenda 2 F1202, F1202 Firmware 2025-03-13 6.5 Medium
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.
CVE-2024-30622 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 9.8 Critical
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.
CVE-2024-30623 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 6.5 Medium
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.
CVE-2024-30629 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 5.7 Medium
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.
CVE-2024-30624 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 8.8 High
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.
CVE-2024-30625 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 8.0 High
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.
CVE-2024-30626 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 8.0 High
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.
CVE-2024-30627 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 8.8 High
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function.
CVE-2024-30630 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 9.8 Critical
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.
CVE-2024-30631 1 Tenda 2 Fh1205, Fh1205 Firmware 2025-03-13 4.3 Medium
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.
CVE-2024-8035 2 Google, Microsoft 2 Chrome, Windows 2025-03-13 4.3 Medium
Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-45621 1 Rocket.chat 1 Rocket.chat 2025-03-13 5.4 Medium
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.
CVE-2024-42903 1 Limesurvey 1 Limesurvey 2025-03-13 6.5 Medium
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
CVE-2024-41251 2 Kashipara, Lopalopa 2 Responsive School Management System, Responsive School Management System 2025-03-13 6.5 Medium
An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.
CVE-2024-36130 1 Ivanti 1 Endpoint Manager Mobile 2025-03-13 9.8 Critical
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
CVE-2024-33844 1 Parrot 1 Anafi Firmware 2025-03-13 7.5 High
The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE.
CVE-2024-33533 1 Zimbra 1 Collaboration 2025-03-13 5.4 Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file and crafting a URL containing its location in the packages parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.
CVE-2024-31844 1 Italtel 1 Embrace 2025-03-13 5.3 Medium
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure of information about the server. An unauthenticated user is able craft specific requests in order to make the application generate an error. Inside an error message, some information about the server is revealed, such as the absolute path of the source code of the application. This kind of information can help an attacker to perform other attacks against the system. This can be exploited without authentication.
CVE-2024-22923 1 Advradius 1 Adv Radius 2025-03-13 9.8 Critical
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.
CVE-2024-30607 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 8.0 High
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.