7.3

CVSS3.1

CVE-2023-42344 -

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 3:16 p.m.

0.0

CVE-2024-33724 - Cross Site Scripting via groupe_id in SOPlanning 1.52.00

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 2:45 p.m.

0.0

CVE-2024-46508 -

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 5:19 a.m.

0.0

CVE-2024-53326 -

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 3:45 p.m.

0.0

CVE-2024-33722 - SQL Injection via statut[] in projets.php of SOPlanning 1.52.00

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 6:30 a.m.

0.0

CVE-2025-69599 - Privilege Escalation via PATH Environment Variable Exposure in RayVentory Scan Engine

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to control the environment is a site-specific misconfiguration.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 7:30 a.m.

0.0

CVE-2025-69690 - Code Execution via Module Installer in pfSense CE 2.7.2

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execut…

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 7:30 a.m.

0.0

CVE-2024-46507 - Server Side Template Injection in Yeti Custom Template Export Allows Remote Code Execution

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 6:30 a.m.

0.0

CVE-2024-45257 -

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 3:30 p.m.

6.1

CVSS3.1

CVE-2023-42345 - Cross‑Site Scripting via updateModelGroups.jsp in Alkacon OpenCms

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

πŸ“… Published: May 8, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 12:59 p.m.
Total resulsts: 349182
Page 35 of 34,919
Β« previous page Β» next page
Filters