8

CVSS3.1

CVE-2024-45084 - IBM Cognos Controller CSV injection

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.

πŸ“… Published: Feb. 19, 2025, 3:24 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 6:15 p.m.

8.8

CVSS3.1

CVE-2024-52902 - IBM Cognos Controller information disclosure

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.

πŸ“… Published: Feb. 19, 2025, 2:50 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 2:42 p.m.

6.9

CVSS4.0

CVE-2025-1464 - Baiyi Cloud Asset Management System admin.house.collect.php sql injection

A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. This issue affects some unknown processing of the file /wuser/admin.house.collect.php. The manipulation of the argument project_id leads to sql injection. The attack may be initi…

πŸ“… Published: Feb. 19, 2025, 1:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-13534 - Small Package Quotes – Worldwide Express Edition <= 5.2.18 - Unauthenticated SQL Injection

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

7.5

CVSS3.1

CVE-2024-13533 - Small Package Quotes – USPS Edition <= 1.3.5 - Unauthenticated SQL Injection

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:28 p.m.

7.5

CVSS3.1

CVE-2024-13483 - LTL Freight Quotes – SAIA Edition <= 2.2.10 - Unauthenticated SQL Injection

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

7.5

CVSS3.1

CVE-2024-13491 - Small Package Quotes – For Customers of FedEx <= 4.3.1 - Unauthenticated SQL Injection

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

7.5

CVSS3.1

CVE-2024-13481 - LTL Freight Quotes – R+L Carriers Edition <= 3.3.4 - Unauthenticated SQL Injection

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2024-13485 - LTL Freight Quotes – ABF Freight Edition <= 3.3.7 - Unauthenticated SQL Injection

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:12 p.m.

7.5

CVSS3.1

CVE-2024-13479 - LTL Freight Quotes – SEFL Edition <= 3.2.4 - Unauthenticated SQL Injection

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ…

πŸ“… Published: Feb. 19, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.
Total resulsts: 349182
Page 6685 of 34,919
Β« previous page Β» next page
Filters