NA - CVE-2024-45284 - An authenticated attacker with high privilege...
An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of privileges causing low impact on...
NA - CVE-2024-45285 - The RFC enabled function module allows a low...
The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module...
NA - CVE-2024-45504 - Cross-site request forgery (CSRF) vulnerability...
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user...
NA - CVE-2024-6173 - 51l3nc3, member of the AXIS OS Bug Bounty...
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour...
NA - CVE-2024-6509 - Marinus Pfund, member of the AXIS OS Bug Bounty...
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device. Axis...
NA - CVE-2024-6979 - Amin Aliakbari, member of the AXIS OS Bug...
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than...
NA - CVE-2024-7784 - During internal Axis Security Development Model...
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a...
NA - CVE-2024-7891 - The Floating Contact Button WordPress plugin...
The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting...
NA - CVE-2024-7955 - The Starbox WordPress plugin before 3.5.2 does...
The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...
NA - CVE-2024-44072 - OS command injection vulnerability exists in...
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected...