7.3

CVSS3.1

CVE-2024-57426 -

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-57673 -

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 9:57 p.m.

7.5

CVSS3.1

CVE-2024-39033 -

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-57392 -

Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-57668 -

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.1

CVSS3.1

CVE-2024-57427 -

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:13 a.m.

9.8

CVSS3.1

CVE-2025-22992 -

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: July 30, 2025, 6:12 p.m.

7.5

CVSS3.1

CVE-2024-36558 -

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2024-57523 -

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 8:06 p.m.

7.5

CVSS3.1

CVE-2024-56889 -

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 2:06 a.m.
Total resulsts: 349182
Page 6834 of 34,919
Β« previous page Β» next page
Filters