5.3

CVSS4.0

CVE-2024-10505 - wuzhicms block.php edit code injection

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the pub…

πŸ“… Published: Oct. 30, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 4:38 p.m.

5.3

CVSS4.0

CVE-2024-10503 - Klokan MapTiler tileserver-gl URL cross site scripting

A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argument key leads to cross site scripting. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Oct. 30, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 7, 2024, 3:30 p.m.

5.3

CVSS4.0

CVE-2024-10502 - ESAFENET CDG FileDirectoryService.java getOneFileDirectory sql injection

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function getOneFileDirectory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument directoryId leads to sql injection. The attack can be…

πŸ“… Published: Oct. 30, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 5:20 p.m.

5.3

CVSS4.0

CVE-2024-10501 - ESAFENET CDG ExamCDGDocService.java findById sql injection

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 5:20 p.m.

5.3

CVSS4.0

CVE-2024-10500 - ESAFENET CDG HookWhiteListService.java sql injection

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched …

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 9:02 p.m.

8.1

CVSS3.1

CVE-2024-42041 -

The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 1, 2024, 12:57 p.m.

6.7

CVSS3.1

CVE-2024-10573 - Mpg123: buffer overflow when writing decoded pcm samples

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is c…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 20, 2025, 6:11 p.m.

5.4

CVSS3.1

CVE-2024-48807 -

Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 7:24 p.m.

9.8

CVSS3.1

CVE-2024-48202 -

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:31 a.m.

8.8

CVSS3.1

CVE-2024-51257 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.
Total resulsts: 343978
Page 7565 of 34,398
Β« previous page Β» next page
Filters