221
|
- |
|
-
|
-
|
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text credentials in the web portal. An attacker can access
the ETIC RAS web portal and view the HTML code, which …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2024-26155
|
2025-01-18 02:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
222
|
- |
|
-
|
-
|
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting in the appliance site
name. The ETIC RAS web server saves the site name and t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-26154
|
2025-01-18 02:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
223
|
- |
|
-
|
-
|
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can force the end user…
|
CWE-352
Origin Validation Error
|
CVE-2024-26153
|
2025-01-18 02:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
224
|
- |
|
-
|
-
|
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.
|
-
|
CVE-2024-57582
|
2025-01-18 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
225
|
- |
|
-
|
-
|
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
|
-
|
CVE-2024-57581
|
2025-01-18 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
226
|
- |
|
-
|
-
|
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
|
-
|
CVE-2024-57580
|
2025-01-18 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
227
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/leaveroom.php. The manipulation of the argument id …
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0531
|
2025-01-18 01:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
228
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/_feedback_system.php. The manipulation o…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0530
|
2025-01-18 01:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
229
|
7.3 |
HIGH
Local
|
microsoft
|
visual_studio_2022
|
Visual Studio Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2025-21405
|
2025-01-18 00:47 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
230
|
7.8 |
HIGH
Local
|
microsoft
|
access 365_apps office
|
Microsoft Access Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2025-21395
|
2025-01-18 00:46 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|