5.3

CVSS4.0

CVE-2024-13204 - kurniaramadhan E-Commerce-PHP blog-details.php sql injection

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /blog-details.php. The manipulation of the argument blog_id leads to sql injection. The attack can be launched remotely. The explo…

📅 Published: Jan. 9, 2025, 2 a.m. 🔄 Last Modified: July 2, 2025, 7:10 p.m.

6.9

CVSS4.0

CVE-2024-13203 - kurniaramadhan E-Commerce-PHP cross-site request forgery

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did no…

📅 Published: Jan. 9, 2025, 2 a.m. 🔄 Last Modified: July 2, 2025, 7:10 p.m.

5.1

CVSS4.0

CVE-2024-13202 - wander-chu SpringBoot-Blog Blog Article PageController.java modifiyArticle cross site scripting

A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Handler. The manipulation of the argument conten…

📅 Published: Jan. 9, 2025, 1:31 a.m. 🔄 Last Modified: Aug. 22, 2025, 4:46 p.m.

5.1

CVSS4.0

CVE-2024-13201 - wander-chu SpringBoot-Blog Admin Attachment AttachtController.java upload unrestricted upload

A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. The manipulation of the argume…

📅 Published: Jan. 9, 2025, 1:31 a.m. 🔄 Last Modified: Aug. 22, 2025, 4:47 p.m.

6.9

CVSS4.0

CVE-2024-13200 - wander-chu SpringBoot-Blog HTTP POST Request BaseInterceptor.java preHandle access control

A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. The manipulation leads to improper access co…

📅 Published: Jan. 9, 2025, 1 a.m. 🔄 Last Modified: Aug. 22, 2025, 4:54 p.m.

5.3

CVSS3.1

CVE-2023-27531 -

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

📅 Published: Jan. 9, 2025, 12:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.6

CVSS3.1

CVE-2024-37372 - nodejs: Permission model improperly processes UNC paths

The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

📅 Published: Jan. 9, 2025, 12:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-13199 - langhsu Mblog Blog System Search Bar search cross site scripting

A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely.…

📅 Published: Jan. 9, 2025, 12:31 a.m. 🔄 Last Modified: Sept. 24, 2025, 7:04 p.m.

6.3

CVSS4.0

CVE-2024-13198 - langhsu Mblog Blog System login observable response discrepancy

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The e…

📅 Published: Jan. 9, 2025, 12:31 a.m. 🔄 Last Modified: Sept. 24, 2025, 7:03 p.m.

5.3

CVSS4.0

CVE-2024-13197 - donglight bookstore电商书城系统说明 AdminUserControlle.java updateUser cross site scripting

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads to cross site scripting. The attack may be in…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Aug. 22, 2025, 9:39 p.m.
Total resulsts: 349182
Page 7218 of 34,919
« previous page » next page
Filters