8.1

CVSS3.1

CVE-2024-45404 - OpenCTI's lack of Rate Limit lead to OTP brute forcing

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication and hijack the accoโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:01 p.m. ๐Ÿ”„ Last Modified: May 17, 2025, 2:05 a.m.

5.3

CVSS4.0

CVE-2024-12489 - code-projects Online Class and Exam Scheduling System term.php sql injection

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/term.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2024, 5:38 p.m.

7.8

CVSS3.0

CVE-2024-11872 - Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability

Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target systeโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:55 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:32 p.m.

8.8

CVSS3.1

CVE-2024-11949 - GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability

GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists withiโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:55 p.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 7:28 p.m.

9.8

CVSS3.1

CVE-2024-11948 - GFI Archiver Telerik Web UI Remote Code Execution Vulnerability

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The โ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:55 p.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 7:32 p.m.

8.8

CVSS3.1

CVE-2024-11947 - GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability

GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The specific flaw exists withinโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:54 p.m. ๐Ÿ”„ Last Modified: Dec. 13, 2024, 7:33 p.m.

8.8

CVSS3.1

CVE-2024-11950 - XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability

XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in that the target must vโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:54 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:31 p.m.

5.3

CVSS4.0

CVE-2024-12488 - code-projects Online Class and Exam Scheduling System subject_update.php sql injection

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/subject_update.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9:31 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2024, 5:37 p.m.

5.3

CVSS4.0

CVE-2024-12487 - code-projects Online Class and Exam Scheduling System room_update.php sql injection

A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/room_update.php. The manipulation of the argument id leads to sql injection. The attack can be launchโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 9 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2024, 5:36 p.m.

5.3

CVSS4.0

CVE-2024-12486 - code-projects Online Class and Exam Scheduling System rank_update.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. Thโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 8:31 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2024, 5:35 p.m.
Total resulsts: 349182
Page 7518 of 34,919
ยซ previous page ยป next page
Filters