4.2

CVSS3.1

CVE-2024-10815 - PostLists <= 2.0.2 - Reflected XSS

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

๐Ÿ“… Published: Jan. 9, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 14, 2025, 3:32 p.m.

5.3

CVSS4.0

CVE-2025-0333 - leiyuxi cy-fast listData sql injection

A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the pโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 5 a.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 4:41 p.m.

6.9

CVSS4.0

CVE-2025-0331 - YunzMall HTTP POST Request ResetpwdController.php changePwd password recovery

A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to weak password rโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 4:31 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0328 - KaiYuanTong ECT Platform HTTP POST Request runCode.php command injection

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipulation of the argument code leads to command iโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 4:31 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-13213 - SingMR HouseRent toAdminUpdateHousePage cross site scripting

A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and mayโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 4 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 6:48 p.m.

5.3

CVSS4.0

CVE-2024-13212 - SingMR HouseRent AddHouseController.java upload unrestricted upload

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate theโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 4 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 5:40 p.m.

5.3

CVSS4.0

CVE-2024-13211 - SingMR HouseRent AdminController.java access control

A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. Thโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 3:31 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 5:41 p.m.

5.1

CVSS4.0

CVE-2024-13210 - donglight bookstore็”ตๅ•†ไนฆๅŸŽ็ณป็ปŸ่ฏดๆ˜Ž AdminBookController. java uploadPicture unrestricted upload

A vulnerability was found in donglight bookstore็”ตๅ•†ไนฆๅŸŽ็ณป็ปŸ่ฏดๆ˜Ž 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leadsโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 3:31 a.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 9:39 p.m.

5.1

CVSS4.0

CVE-2024-13209 - Redaxo CMS Structure Management Page index.php cross site scripting

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Aโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 3 a.m. ๐Ÿ”„ Last Modified: June 24, 2025, 2:30 p.m.

8.5

CVSS4.0

CVE-2024-13206 - REVE Antivirus reveinstall default permission

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit haโ€ฆ

๐Ÿ“… Published: Jan. 9, 2025, 3 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345363
Page 6835 of 34,537
ยซ previous page ยป next page
Filters