5.3

CVSS4.0

CVE-2024-12892 - code-projects Online Exam Mastering System sign.php cross site scripting

A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. The manipulation of the argument name/gender/college leads to cross site scripting. The attack can b…

πŸ“… Published: Dec. 22, 2024, 7:31 a.m. πŸ”„ Last Modified: April 3, 2025, 4:33 p.m.

5.3

CVSS4.0

CVE-2024-12891 - code-projects Online Exam Mastering System account.php sql injection

A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has…

πŸ“… Published: Dec. 22, 2024, 6:31 a.m. πŸ”„ Last Modified: April 3, 2025, 4:34 p.m.

5.3

CVSS4.0

CVE-2024-12890 - code-projects Online Exam Mastering System update.php sql injection

A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /update.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. The attack may be initiated remotely. The exploi…

πŸ“… Published: Dec. 22, 2024, 6 a.m. πŸ”„ Last Modified: April 3, 2025, 4:34 p.m.

4.3

CVSS3.1

CVE-2024-11852 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arr…

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes i…

πŸ“… Published: Dec. 22, 2024, 1:41 a.m. πŸ”„ Last Modified: April 8, 2026, 5:25 p.m.

7.5

CVSS3.1

CVE-2024-56375 -

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (and, shortly afterwards, writes to) this array duri…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:54 p.m.

5.4

CVSS3.1

CVE-2024-56313 -

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitr…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

4.3

CVSS3.1

CVE-2024-56378 - Poppler: out-of-bounds read

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.4

CVSS3.1

CVE-2024-56314 -

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project. When a user clicks on the project name to access it, the crafted payload is executed, potentially enabling the exec…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

5.4

CVSS3.1

CVE-2024-56312 -

A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project Dashboard. When a user clicks on the project Dashboard name, the crafted payload is executed, potentially …

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.

8.8

CVSS3.1

CVE-2024-56311 -

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into accessing a calendar event's notes, which triggers a logout request and terminates their session. This v…

πŸ“… Published: Dec. 22, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:43 p.m.
Total resulsts: 343923
Page 6868 of 34,393
Β« previous page Β» next page
Filters