NA - CVE-2024-50402 - A use of externally-controlled format string...
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have...
NA - CVE-2024-50403 - A use of externally-controlled format string...
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have...
NA - CVE-2024-50404 - A link following vulnerability has been...
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to...
NA - CVE-2024-53691 - A link following vulnerability has been...
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to...
NA - CVE-2024-54143 - openwrt/asu is an image on demand server for...
openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it...
NA - CVE-2024-54749 - Ubiquiti U7-Pro 7.0.35 was discovered to...
Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed by the Supplier because the...
NA - CVE-2024-55268 - A Reflected Cross Site Scripting (XSS)...
A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute...
NA - CVE-2024-11220 - A local low-level user on the server machine...
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx...
NA - CVE-2024-42494 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud...
NA - CVE-2024-47043 - Ruijie Reyee OS versions 2.206.x up to but not...
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone number and part of the email address.