NA - CVE-2024-11220 - A local low-level user on the server machine...
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx...
NA - CVE-2024-42494 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud...
NA - CVE-2024-47043 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.
NA - CVE-2024-47547 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
NA - CVE-2024-48703 - PhpGurukul Medical Card Generation System v1.0...
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.
NA - CVE-2024-48871 - The affected product is vulnerable to a...
The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before...
NA - CVE-2024-51727 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and cause a denial-of-service attack...
NA - CVE-2024-52320 - The affected product is vulnerable to a command...
The affected product is vulnerable to a command injection. An unauthenticated attacker could send commands through a malicious HTTP request which could result in remote code execution.
NA - CVE-2024-52558 - The affected product is vulnerable to an...
The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP request, which could allow the attacker to crash the program.
NA - CVE-2024-45722 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.