5.3

CVSS4.0

CVE-2024-12348 - Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scrip…

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross si…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: June 4, 2025, 7:13 p.m.

9.1

CVSS3.1

CVE-2024-53441 -

An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48956 -

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-53450 -

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 10:34 p.m.

9.8

CVSS3.1

CVE-2022-38947 -

SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: May 17, 2025, 1:57 a.m.

4.3

CVSS3.1

CVE-2024-55565 - nanoid: nanoid mishandles non-integer values

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2022-38946 -

Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: May 17, 2025, 1:58 a.m.

7.5

CVSS3.1

CVE-2024-40582 -

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 1:41 a.m.

8.8

CVSS3.1

CVE-2024-55579 -

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, Novemb…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-54926 -

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: Dec. 11, 2024, 5:24 p.m.
Total resulsts: 349182
Page 7585 of 34,919
Β« previous page Β» next page
Filters