Aggregator
CVE-2024-4120 | Tenda W15E 15.11.0.14 /goform/modifyIpMacBind formIPMacBindModify stack-based overflow
CVE-2024-4121 | Tenda W15E 15.11.0.14 formQOSRuleDel qosIndex stack-based overflow
CVE-2024-4122 | Tenda W15E 15.11.0.14 /goform/setDebugCfg formSetDebugCfg enable/level/module stack-based overflow
CVE-2024-4123 | Tenda W15E 15.11.0.14 /goform/SetPortMapping formSetPortMapping stack-based overflow
CVE-2024-4124 | Tenda W15E 15.11.0.14 SetRemoteWebManage formSetRemoteWebManage remoteIP stack-based overflow
CVE-2024-4125 | Tenda W15E 15.11.0.14 /goform/setStaticRoute formSetStaticRoute staticRouteIndex stack-based overflow
CVE-2024-4126 | Tenda W15E 15.11.0.14 /goform/SetSysTimeCfg formSetSysTime manualTime stack-based overflow
CVE-2024-4127 | Tenda W15E 15.11.0.14 guestWifiRuleRefresh qosGuestDownstream stack-based overflow
CVE-2024-3994 | Tutor LMS Plugin up to 2.6.2 on WordPress Shortcode tutor_instructor_list cross site scripting (ID 3076302)
CVE-2024-3553 | Tutor LMS Plugin up to 2.6.2 on WordPress Options Update authorization (ID 3076302)
CVE-2024-3161 | Jeg Elementor Kit Plugin up to 2.6.4 on WordPress Countdown Widget cross site scripting
CVE-2024-0334 | Jeg Elementor Kit Plugin up to 2.6.4 on WordPress Widget URL Custom Attribute cross site scripting
CVE-2024-4115 | Tenda W15E 15.11.0.14 /goform/AddDnsForward formAddDnsForward DnsForwardRule stack-based overflow
CVE-2024-4116 | Tenda W15E 15.11.0.14 /goform/DelDhcpRule formDelDhcpRule delDhcpIndex stack-based overflow
CVE-2024-4117 | Tenda W15E 15.11.0.14 /goform/DelPortMapping formDelPortMapping portMappingIndex stack-based overflow
CVE-2024-4118 | Tenda W15E 15.11.0.14 /goform/addIpMacBind formIPMacBindAdd IPMacBindRule stack-based overflow
Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification
Overview Recently, NSFOCUS CERT detected that Fortinet has issued a security notification and fixed the identity authentication bypass vulnerability in FortiOS and FortiProxy (CVE-2024-55591). Unauthenticated attackers can bypass system identity authentication by sending special packets to the Node.js websocket module, thus obtaining super administrator permissions of the target system. The CVSS score is 9.8. At […]
The post Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification appeared first on NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks..
The post Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification appeared first on Security Boulevard.