|
312891
|
- |
|
-
|
-
|
Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.
In order to exploit this vulnerability, one h…
|
-
|
CVE-2024-3659
|
2024-08-9 00:35 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312892
|
7.8 |
HIGH
Local
|
enjayworld
|
enjay_crm
|
An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
|
NVD-CWE-noinfo
|
CVE-2024-41309
|
2024-08-9 00:35 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312893
|
9.8 |
CRITICAL
Network
|
oretnom23
|
computer_laboratory_management_system
|
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2024-34480
|
2024-08-9 00:35 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312894
|
- |
|
-
|
-
|
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute…
|
-
|
CVE-2024-42395
|
2024-08-9 00:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312895
|
9.8 |
CRITICAL
Network
|
gl-inet
|
mt6000_firmware a1300_firmware x300b_firmware ax1800_firmware axt1800_firmware mt2500_firmware mt3000_firmware x3000_firmware xe3000_firmware xe300_firmware e750_firmwar…
|
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/…
|
CWE-78
OS Command
|
CVE-2024-39228
|
2024-08-9 00:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312896
|
9.8 |
CRITICAL
Network
|
gl-inet
|
mt6000_firmware a1300_firmware x300b_firmware ax1800_firmware axt1800_firmware mt2500_firmware mt3000_firmware x3000_firmware xe3000_firmware xe300_firmware e750_firmwar…
|
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-39225
|
2024-08-9 00:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312897
|
- |
|
-
|
-
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper re…
|
-
|
CVE-2024-38888
|
2024-08-9 00:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312898
|
7.5 |
HIGH
Network
|
janobe
|
school_attendence_monitoring_system school_event_management_system paypal credit_card debit_card_payment
|
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and re…
|
CWE-89
SQL Injection
|
CVE-2024-33964
|
2024-08-9 00:29 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312899
|
7.5 |
HIGH
Network
|
janobe
|
school_attendence_monitoring_system school_event_management_system paypal credit_card debit_card_payment
|
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and re…
|
CWE-89
SQL Injection
|
CVE-2024-33963
|
2024-08-9 00:29 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312900
|
7.5 |
HIGH
Network
|
janobe
|
school_attendence_monitoring_system school_event_management_system paypal credit_card debit_card_payment
|
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and re…
|
CWE-89
SQL Injection
|
CVE-2024-33962
|
2024-08-9 00:29 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|