5.9

CVSS3.1

CVE-2024-56085 -

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 1:48 a.m.

4.8

CVSS3.1

CVE-2024-55100 -

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 4:25 p.m.

4.8

CVSS3.1

CVE-2024-37773 -

An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:14 p.m.

7.1

CVSS3.1

CVE-2024-56084 -

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:47 p.m.

7.1

CVSS3.1

CVE-2024-56086 -

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 1:50 a.m.

9.8

CVSS3.1

CVE-2024-55085 -

GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 1:57 a.m.

9.8

CVSS3.1

CVE-2024-29671 -

Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2024-37774 -

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 6:15 p.m.

5.4

CVSS3.1

CVE-2024-55452 -

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated usโ€ฆ

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 3:20 p.m.

7.2

CVSS3.1

CVE-2024-55103 -

Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

๐Ÿ“… Published: Dec. 16, 2024, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 4:26 p.m.
Total resulsts: 349182
Page 7459 of 34,919
ยซ previous page ยป next page
Filters