41
|
- |
|
-
|
-
|
Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.
New
|
-
|
CVE-2024-25253
|
2024-11-12 08:15 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
42
|
- |
|
-
|
-
|
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
New
|
-
|
CVE-2024-23983
|
2024-11-12 08:15 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
43
|
- |
|
-
|
-
|
Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing fo…
Update
|
-
|
CVE-2024-40117
|
2024-11-12 08:15 |
2024-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
44
|
- |
|
-
|
-
|
An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for S…
Update
|
-
|
CVE-2024-40116
|
2024-11-12 08:15 |
2024-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
45
|
5.4 |
MEDIUM
Network
|
solar-log
|
2000_pm\+_firmware
|
A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2023-46344
|
2024-11-12 08:15 |
2024-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
46
|
9.8 |
CRITICAL
Network
solar-log
|
solar-log_250_firmware solar-log_300_firmware solar-log_500_firmware solar-log_800e_firmware solar-log_1000_firmware solar-log_1000_pm\+_firmware solar-log_1200_firmware solar-lo…
|
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up…
Update
|
NVD-CWE-noinfo
|
CVE-2022-47767
|
2024-11-12 08:15 |
2023-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
47
|
6.5 |
MEDIUM
Network
|
bkw
|
solar-log_500_firmware
|
An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read b…
Update
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-34544
|
2024-11-12 08:15 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
48
|
7.5 |
HIGH
Network
bkw
|
solar-log_500_firmware
|
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-34543
|
2024-11-12 08:15 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
49
|
- |
|
-
|
-
|
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= fiel…
New
|
-
|
CVE-2024-51026
|
2024-11-12 06:15 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
50
|
- |
|
-
|
-
|
The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity…
New
|
-
|
CVE-2024-46966
|
2024-11-12 06:15 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|