5.3

CVSS4.0

CVE-2024-13196 - donglight bookstore电商书城系统说明 BookInfoController.java BookSearchList cross site scripting

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore/web/controller/BookInfoController.java. The manipulation of the argument keywords leads to cross si…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Aug. 22, 2025, 9:40 p.m.

5.4

CVSS3.1

CVE-2024-56377 -

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (whi…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 16, 2025, 9:10 p.m.

9.6

CVSS3.1

CVE-2024-55224 -

An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: June 20, 2025, 6:30 p.m.

9.1

CVSS3.1

CVE-2024-46505 -

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-55494 -

A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-42898 -

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: June 24, 2025, 2:27 p.m.

8

CVSS3.1

CVE-2024-54887 -

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: June 20, 2025, 6:35 p.m.

5.4

CVSS3.1

CVE-2024-55226 -

Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: June 24, 2025, 2:01 p.m.

7.5

CVSS3.1

CVE-2024-56113 -

Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-56376 -

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 16, 2025, 9:10 p.m.
Total resulsts: 349182
Page 7219 of 34,919
« previous page » next page
Filters