CVE-2024-55553 |
Description: In FRRouting (FRR) before 10.3, it is possible for an attacker to trigger repeated RIB revalidation by sending approximately 500 RPKI updates, potentially leading to prolonged revalidation times and a Denial of Service (DoS) scenario.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55529 |
Description: Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55408 |
Description: An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55407 |
Description: An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55076 |
Description: Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
CVSS: HIGH (8.1) EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55075 |
Description: Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
CVSS: MEDIUM (4.3) EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-55074 |
Description: The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
CVSS: HIGH (8.8) EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-54880 |
Description: SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-54879 |
Description: SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|
CVE-2024-54764 |
Description: An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
EPSS Score: 0.04%
January 7th, 2025 (6 months ago)
|