7.2

CVSS3.1

CVE-2024-36694 -

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 3:36 p.m.

4.7

CVSS3.1

CVE-2024-56173 -

In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: June 5, 2025, 8:58 p.m.

6.1

CVSS3.1

CVE-2024-55492 -

Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: July 17, 2025, 5:19 p.m.

4.1

CVSS3.1

CVE-2024-55089 -

Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: Feb. 20, 2026, 8:25 p.m.

4.3

CVSS3.1

CVE-2024-49201 -

Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: Dec. 21, 2024, 12:15 a.m.

7.5

CVSS3.1

CVE-2024-53580 - iperf: Denial of Service in iperf Due to Improper JSON Handling

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

8.8

CVSS3.1

CVE-2024-55505 -

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 1:54 a.m.

4.3

CVSS3.1

CVE-2024-55231 -

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's info…

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 4:30 p.m.

5.4

CVSS3.1

CVE-2024-55232 -

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: March 28, 2025, 4:21 p.m.

8.8

CVSS3.1

CVE-2024-55088 -

GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

πŸ“… Published: Dec. 18, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 1:56 a.m.
Total resulsts: 343924
Page 6903 of 34,393
Β« previous page Β» next page
Filters