Search Results (Refine Search)
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2024-30546 |
Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-30220 |
Command injection vulnerability in MZK-MF300N all firmware versions allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-30219 |
Active debug code vulnerability exists in MZK-MF300N all firmware versions. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-29219 |
Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-29218 |
Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-28957 |
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-28894 |
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-28099 |
VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-26023 |
OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-23911 |
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet. Published: April 15, 2024; 7:15:08 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-23486 |
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials. Published: April 15, 2024; 7:15:07 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31940 |
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Extra Product Options Builder for WooCommerce.This issue affects Extra Product Options Builder for WooCommerce: from n/a through 1.2.104. Published: April 15, 2024; 6:15:12 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31938 |
Cross-Site Request Forgery (CSRF) vulnerability in Themeinwp NewsXpress.This issue affects NewsXpress: from n/a through 1.0.7. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31933 |
Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31923 |
Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page.This issue affects Feather Login Page: from n/a through 1.1.5. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31922 |
Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31921 |
Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31920 |
Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Currency per Product for WooCommerce.This issue affects Currency per Product for WooCommerce: from n/a through 1.6.0. Published: April 15, 2024; 6:15:11 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31434 |
Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6. Published: April 15, 2024; 6:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |
CVE-2024-31433 |
Cross-Site Request Forgery (CSRF) vulnerability in The Events Calendar.This issue affects The Events Calendar: from n/a through 6.3.0. Published: April 15, 2024; 6:15:10 AM -0400 |
V3.x:(not available) V2.0:(not available) |