9.8

CVSS3.1

CVE-2024-4300 - E-WEBInformationCo. FS-EZViewer(Web) - Sensitive Data Exposure

E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and da…

πŸ“… Published: April 29, 2024, 3:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-4299 - HGiga iSherlock - Command Injection

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enablin…

πŸ“… Published: April 29, 2024, 3:15 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 2:27 p.m.

7.2

CVSS3.1

CVE-2024-4298 - HGiga iSherlock - Command Injection

The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execut…

πŸ“… Published: April 29, 2024, 2:39 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 2:29 p.m.

4.9

CVSS3.1

CVE-2024-4297 - HGiga iSherlock - Arbitrary File Download

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.

πŸ“… Published: April 29, 2024, 2:28 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 2:42 p.m.

4.9

CVSS3.1

CVE-2024-4296 - HGiga iSherlock - Arbitrary File Download

The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.

πŸ“… Published: April 29, 2024, 2:08 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 2:46 p.m.

6.5

CVSS3.1

CVE-2024-34020 -

A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.

πŸ“… Published: April 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2023-46960 -

Buffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp module.

πŸ“… Published: April 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-32493 -

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.

πŸ“… Published: April 29, 2024, midnight πŸ”„ Last Modified: Sept. 2, 2025, 9:19 p.m.

9.8

CVSS3.1

CVE-2024-32491 -

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be executed if this location is publicly available t…

πŸ“… Published: April 29, 2024, midnight πŸ”„ Last Modified: Sept. 2, 2025, 9:21 p.m.

7.1

CVSS3.1

CVE-2024-32492 -

An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.

πŸ“… Published: April 29, 2024, midnight πŸ”„ Last Modified: Sept. 2, 2025, 9:19 p.m.
Total resulsts: 349182
Page 10137 of 34,919
Β« previous page Β» next page
Filters