CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-30584

    Last Modified: 10 Apr 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30585

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30586

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2024-30587

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    4.3
    Medium

    CVE-2024-30588

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30590

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

    Published: 28 Mar 2024
    8.8
    High

    CVE-2024-30591

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    8
    High

    CVE-2024-30592

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2024-30593

    Last Modified: 10 Apr 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30594

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2024-30595

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2024-30596

    Last Modified: 13 Mar 2025

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30597

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

    Published: 28 Mar 2024
    8
    High

    CVE-2024-30600

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

    Published: 28 Mar 2024
    8
    High

    CVE-2024-30601

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2024-30602

    Last Modified: 10 Apr 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30603

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    7.5
    High

    CVE-2024-30604

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.

    Published: 28 Mar 2024
    8
    High

    CVE-2024-30606

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

    Published: 28 Mar 2024
    8
    High

    CVE-2024-30607

    Last Modified: 13 Mar 2025

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

    Published: 28 Mar 2024
    6.3
    Medium

    CVE-2024-31062

    Last Modified: 3 Apr 2025

    Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

    Published: 28 Mar 2024
    6.4
    Medium

    CVE-2024-31063

    Last Modified: 3 Apr 2025

    Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.

    Published: 28 Mar 2024
    6.1
    Medium

    CVE-2024-31064

    Last Modified: 3 Apr 2025

    Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

    Published: 28 Mar 2024
    6.1
    Medium

    CVE-2024-31065

    Last Modified: 3 Apr 2025

    Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.

    Published: 28 Mar 2024
    7.5
    High

    CVE-2021-31156

    Last Modified: 15 Apr 2026

    Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2023-25341

    Last Modified: 15 Apr 2026

    A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2023-50969

    Last Modified: 15 Apr 2026

    Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

    Published: 28 Mar 2024
    8.4
    High

    CVE-2024-23727

    Last Modified: 15 Apr 2026

    The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.

    Published: 28 Mar 2024
    6.1
    Medium

    CVE-2024-28091

    Last Modified: 15 Apr 2026

    Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User Defined Service in managed_services_add.asp (the victim must click an X for a deletion).

    Published: 28 Mar 2024
    8.8
    High

    CVE-2024-3010

    Last Modified: 15 Jan 2025

    A vulnerability was found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this issue is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258296. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-3009

    Last Modified: 15 Jan 2025

    A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    7.1
    High

    CVE-2024-0980

    Last Modified: 15 Apr 2026

    The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

    Published: 27 Mar 2024
    8.8
    High

    CVE-2024-3008

    Last Modified: 8 Apr 2025

    A vulnerability, which was classified as critical, was found in Tenda FH1205 2.0.0.7(775). Affected is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258294 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    8.8
    High

    CVE-2024-3007

    Last Modified: 15 Jan 2025

    A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7(775). This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258293 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    8.8
    High

    CVE-2024-3006

    Last Modified: 15 Jan 2025

    A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument entrys leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258292. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    3.5
    Low

    CVE-2024-3004

    Last Modified: 3 Mar 2025

    A vulnerability was found in code-projects Online Book System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Product.php. The manipulation of the argument value leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-258206 is the identifier assigned to this vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-3003

    Last Modified: 3 Mar 2025

    A vulnerability has been found in code-projects Online Book System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cart.php. The manipulation of the argument quantity/remove leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258205 was assigned to this vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-3002

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in code-projects Online Book System 1.0. Affected is an unknown function of the file /description.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258204.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2024-0079

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest VM can cause a NULL-pointer dereference in the host. A successful exploit of this vulnerability may lead to denial of service.

    Published: 27 Mar 2024
    7.8
    High

    CVE-2024-0077

    Last Modified: 15 Apr 2026

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources for which the guest OS is not authorized. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 27 Mar 2024
    6.1
    Medium

    CVE-2024-0075

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user may cause a NULL-pointer dereference by accessing passed parameters the validity of which has not been checked. A successful exploit of this vulnerability may lead to denial of service and limited information disclosure.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2024-0078

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

    Published: 27 Mar 2024
    7.1
    High

    CVE-2024-0074

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Linux contains a vulnerability where an attacker may access a memory location after the end of the buffer. A successful exploit of this vulnerability may lead to denial of service and data tampering.

    Published: 27 Mar 2024
    7.8
    High

    CVE-2024-0073

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer when the driver is performing an operation at a privilege level that is higher than the minimum level required. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 27 Mar 2024
    7.8
    High

    CVE-2024-0071

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-3001

    Last Modified: 21 Feb 2025

    A vulnerability, which was classified as critical, has been found in code-projects Online Book System 1.0. This issue affects some unknown processing of the file /Product.php. The manipulation of the argument value leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258203.

    Published: 27 Mar 2024
    7.3
    High

    CVE-2024-3000

    Last Modified: 21 Feb 2025

    A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258202 is the identifier assigned to this vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2999

    Last Modified: 5 Mar 2025

    A vulnerability classified as critical has been found in Campcodes Online Art Gallery Management System 1.0. This affects an unknown part of the file /admin/adminHome.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258201 was assigned to this vulnerability.

    Published: 27 Mar 2024
    2.4
    Low

    CVE-2024-2998

    Last Modified: 12 Jun 2025

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store Name/Store Address leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258200. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024
    2.4
    Low

    CVE-2024-2997

    Last Modified: 12 Jun 2025

    A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Name/Unit Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258199. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Mar 2024