High - CVE-2024-11981 - Certain models of routers from Billion Electric...
Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.
NA - CVE-2024-11013 - Command Injection vulnerability in NEC...
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier...
NA - CVE-2024-11014 - Cross-site request forgery (CSRF) vulnerability...
Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack...
NA - CVE-2024-11481 - A vulnerability in ESM 11.6.10 allows...
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without...
NA - CVE-2024-11482 - A vulnerability in ESM 11.6.10 allows...
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
High - CVE-2024-11982 - Certain models of routers from Billion Electric...
Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve...
High - CVE-2024-11983 - Certain models of routers from Billion Electric...
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a...
NA - CVE-2024-9044 - A XML External Entity (XXE) vulnerability has...
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
NA - CVE-2024-50357 - FutureNet NXR series routers provided by...
FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly...