Search
Search Results (24 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-20104 | 5 Google, Linuxfoundation, Mediatek and 2 more | 25 Android, Yocto, Mt6781 and 22 more | 2025-04-24 | 8.4 High |
| In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772. | ||||
| CVE-2023-24181 | 1 Openwrt | 1 Luci | 2025-02-11 | 5.4 Medium |
| LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm. | ||||
| CVE-2020-10871 | 1 Openwrt | 1 Luci | 2024-11-21 | 5.3 Medium |
| In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no plan to restrict the information further | ||||
| CVE-2019-12272 | 1 Openwrt | 1 Luci | 2024-11-21 | N/A |
| In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability. | ||||