4.3

CVSS3.1

CVE-2024-12305 - Object-Level Access Control Vulnerability Allows Unauthorized Access to Student Grades in Unifiedtr…

An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerab…

📅 Published: Dec. 9, 2024, 8:49 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9651 - Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

📅 Published: Dec. 9, 2024, 6 a.m. 🔄 Last Modified: May 6, 2025, 9:24 p.m.

5.3

CVSS4.0

CVE-2024-12360 - code-projects Online Class and Exam Scheduling System class_update.php sql injection

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The explo…

📅 Published: Dec. 9, 2024, 5 a.m. 🔄 Last Modified: Dec. 10, 2024, 11:33 p.m.

5.3

CVSS4.0

CVE-2024-12359 - code-projects Admin Dashboard vendor_management.php cross site scripting

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit…

📅 Published: Dec. 9, 2024, 5 a.m. 🔄 Last Modified: Dec. 10, 2024, 11:34 p.m.

5.3

CVSS4.0

CVE-2024-12358 - WeiYe-Jing datax-web add os command injection

A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclo…

📅 Published: Dec. 9, 2024, 4:31 a.m. 🔄 Last Modified: Dec. 10, 2024, 11:34 p.m.

6.9

CVSS4.0

CVE-2024-12357 - SourceCodester Best House Rental Management System index.php file inclusion

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exp…

📅 Published: Dec. 9, 2024, 4:31 a.m. 🔄 Last Modified: Dec. 10, 2024, 11:35 p.m.

5.9

CVSS3.1

CVE-2024-53285 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensit…

📅 Published: Dec. 9, 2024, 3:38 a.m. 🔄 Last Modified: Aug. 4, 2025, 7:07 p.m.

5.9

CVSS3.1

CVE-2024-53284 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing n…

📅 Published: Dec. 9, 2024, 3:32 a.m. 🔄 Last Modified: Aug. 4, 2025, 7:07 p.m.

5.9

CVSS3.1

CVE-2024-53283 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing no…

📅 Published: Dec. 9, 2024, 3:31 a.m. 🔄 Last Modified: Aug. 4, 2025, 7:07 p.m.

5.9

CVSS3.1

CVE-2024-53282 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containin…

📅 Published: Dec. 9, 2024, 3:30 a.m. 🔄 Last Modified: Aug. 4, 2025, 7:08 p.m.
Total resulsts: 349182
Page 7583 of 34,919
« previous page » next page
Filters