7.5

CVSS3.1

CVE-2024-53522 -

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46603 -

An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:14 p.m.

7.5

CVSS3.1

CVE-2024-46601 -

Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:13 p.m.

8.8

CVSS3.1

CVE-2024-55555 -

Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2022-41573 -

An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50660 -

File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:47 p.m.

7.8

CVSS3.1

CVE-2024-55412 -

A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disc…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-48245 -

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which a…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 4:06 p.m.

8.1

CVSS3.1

CVE-2022-45186 -

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:33 p.m.

9.8

CVSS3.1

CVE-2022-41572 -

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 3:10 p.m.
Total resulsts: 349182
Page 7269 of 34,919
Β« previous page Β» next page
Filters