6.9

CVSS4.0

CVE-2024-10599 - Tongda OA 2017 package_static_resources.php resource consumption

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the file /inc/package_static_resources.php. The manipulation leads to resource consumption. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Oct. 31, 2024, 9:31 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:44 p.m.

6.9

CVSS4.0

CVE-2024-10598 - Tongda OA Annual Leave data.php improper authorization

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization. The attack can be initiat…

πŸ“… Published: Oct. 31, 2024, 9:31 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:44 p.m.

6.5

CVSS3.1

CVE-2024-6479 - SIP Reviews Shortcode for WooCommerce <= 1.2.3 - Authenticated (Contributor+) SQL Injection

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara…

πŸ“… Published: Oct. 31, 2024, 9:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-6480 - SIP Reviews Shortcode for WooCommerce <= 1.2.3 - Authenticated (Contributor+) Cross-Site Scripting

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied …

πŸ“… Published: Oct. 31, 2024, 9:30 p.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS4.0

CVE-2024-10597 - ESAFENET CDG PolicyActionService.java delPolicyAction sql injection

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Oct. 31, 2024, 9 p.m. πŸ”„ Last Modified: Nov. 6, 2024, 4:28 p.m.

5.3

CVSS4.0

CVE-2024-10596 - ESAFENET CDG EncryptPolicyTypeService.java delEntryptPolicySort sql injection

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remo…

πŸ“… Published: Oct. 31, 2024, 9 p.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:20 p.m.

5.3

CVSS4.0

CVE-2024-10595 - ESAFENET CDG PublicDocInfoAjax.java delDifferCourseList sql injection

A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql injection. The attack can be launched remotely. The …

πŸ“… Published: Oct. 31, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 8:57 p.m.

5.3

CVSS4.0

CVE-2024-10594 - ESAFENET CDG FileDirectoryService.java docHistory sql injection

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument fileId leads to sql injection. It is possible to launch the attack remote…

πŸ“… Published: Oct. 31, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 5, 2024, 5:05 p.m.

10

CVSS3.1

CVE-2024-51482 - Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.

πŸ“… Published: Oct. 31, 2024, 6:07 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:49 p.m.

0

CVSS3.1

CVE-2024-50356 - Press has a potential 2FA bypass

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by bypassing the 2FA. Onl…

πŸ“… Published: Oct. 31, 2024, 6:02 p.m. πŸ”„ Last Modified: Nov. 1, 2024, 2:35 p.m.
Total resulsts: 344045
Page 7560 of 34,405
Β« previous page Β» next page
Filters