NA - CVE-2024-35244 - There are several hidden accounts. Some of them...
There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to...
NA - CVE-2024-36248 - API keys for some cloud services are hardcoded...
API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective...
NA - CVE-2024-36249 - Cross-site scripting vulnerability exists in...
Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be...
NA - CVE-2024-36251 - The web interface of the affected devices...
The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed...
NA - CVE-2024-36254 - Out-of-bounds read vulnerability exists in...
Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.
NA - CVE-2024-47257 - Florent Thiéry has found that selected Axis...
Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released...
NA - CVE-2024-6831 - Seth Fogie, member of AXIS Camera Station Pro...
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove views without the necessary permission due to a client-side-only check. Axis...
NA - CVE-2024-8160 - Erik de Jong, member of the AXIS OS Bug Bounty...
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to...
NA - CVE-2024-8772 - 51l3nc3, member of the AXIS OS Bug Bounty...
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the...
High - CVE-2024-9504 - The Booking calendar, Appointment Booking...
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to...