7.3

CVSS3.1

CVE-2024-41767 - IBM Engineering Lifecycle Optimization - Publishing SQL injection

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

πŸ“… Published: Jan. 4, 2025, 2:27 p.m. πŸ”„ Last Modified: March 21, 2025, 2:24 p.m.

6.5

CVSS3.1

CVE-2024-41768 - IBM Engineering Lifecycle Optimization - Publishing unhandled SLL exception

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state.

πŸ“… Published: Jan. 4, 2025, 2:26 p.m. πŸ”„ Last Modified: March 21, 2025, 2:26 p.m.

6.9

CVSS4.0

CVE-2025-0210 - Campcodes School Faculty Scheduling System ajax.php sql injection

A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launc…

πŸ“… Published: Jan. 4, 2025, 2 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 9:20 p.m.

8.8

CVSS3.1

CVE-2024-10957 - UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a P…

πŸ“… Published: Jan. 4, 2025, 1:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0208 - code-projects Online Shoe Store summary.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /summary.php. The manipulation of the argument tid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to …

πŸ“… Published: Jan. 4, 2025, 1 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 9:28 p.m.

6.9

CVSS4.0

CVE-2025-0207 - code-projects Online Shoe Store login.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The …

πŸ“… Published: Jan. 4, 2025, 12:31 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 9:27 p.m.

6.9

CVSS4.0

CVE-2025-0206 - code-projects Online Shoe Store index.php access control

A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed t…

πŸ“… Published: Jan. 4, 2025, noon πŸ”„ Last Modified: Jan. 22, 2025, 3:24 p.m.

6.5

CVSS3.1

CVE-2024-12195 - WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt cha…

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 du…

πŸ“… Published: Jan. 4, 2025, 11:24 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-12279 - WP Social AutoConnect <= 4.6.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forg…

πŸ“… Published: Jan. 4, 2025, 11:16 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

6.4

CVSS3.1

CVE-2024-12475 - WP Multi Store Locator <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…

πŸ“… Published: Jan. 4, 2025, 11:16 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.
Total resulsts: 345005
Page 6867 of 34,501
Β« previous page Β» next page
Filters