Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-11 CVE-2024-11064 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-11 CVE-2024-11065 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-11 CVE-2024-11016 SQL Injection vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
network
low complexity
vice CWE-89
critical
9.8
2024-11-11 CVE-2024-11019 Cross-site Scripting vulnerability in Vice Webopac 7.1.20160701
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
network
low complexity
vice CWE-79
6.1
2024-11-11 CVE-2024-52350 Cross-site Scripting vulnerability in Crm2Go
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.
network
low complexity
crm2go CWE-79
5.4
2024-11-11 CVE-2024-52351 Cross-site Scripting vulnerability in BU Slideshow
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boston University (IS&T) BU Slideshow allows Stored XSS.This issue affects BU Slideshow: from n/a through 2.3.10.
network
low complexity
bu CWE-79
5.4
2024-11-11 CVE-2024-52352 Cross-site Scripting vulnerability in Miloco Postcasa Shortcode
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andrew Milo Postcasa Shortcode allows DOM-Based XSS.This issue affects Postcasa Shortcode: from n/a through 1.0.
network
low complexity
miloco CWE-79
5.4
2024-11-11 CVE-2024-52353 Cross-site Scripting vulnerability in Sharethepractice Christian Science Bible Lesson Subjects
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gabriel Serafini Christian Science Bible Lesson Subjects allows DOM-Based XSS.This issue affects Christian Science Bible Lesson Subjects: from n/a through 2.0.
network
low complexity
sharethepractice CWE-79
5.4
2024-11-11 CVE-2024-52354 Cross-site Scripting vulnerability in Coolplugins web Stories Widgets for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Web Stories Widgets For Elementor allows Stored XSS.This issue affects Web Stories Widgets For Elementor: from n/a through 1.1.
network
low complexity
coolplugins CWE-79
5.4
2024-11-11 CVE-2024-52355 Cross-site Scripting vulnerability in Hyumika Openstreetmap
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hyumika OSM – OpenStreetMap allows Stored XSS.This issue affects OSM – OpenStreetMap: from n/a through 6.1.2.
network
low complexity
hyumika CWE-79
5.4