9.8

CVSS3.1

CVE-2024-54932 -

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 24, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-54930 -

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: Dec. 12, 2024, 6:15 p.m.

9.8

CVSS3.1

CVE-2024-54924 -

A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 14, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-54922 -

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: Dec. 12, 2024, 6:15 p.m.

8.8

CVSS3.1

CVE-2024-50626 -

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: June 27, 2025, 4:08 p.m.

8

CVSS3.1

CVE-2024-50625 -

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when co…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: June 27, 2025, 4:07 p.m.

4.2

CVSS3.1

CVE-2024-12369 - Elytron-oidc-client: oidc authorization code injection

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-55563 -

Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents propagation of certain Lightning channel tran…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: May 22, 2025, 4:56 p.m.

5.4

CVSS3.1

CVE-2024-54935 -

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: Dec. 11, 2024, 4:51 p.m.

9.8

CVSS3.1

CVE-2024-54931 -

A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 24, 2025, 3:12 p.m.
Total resulsts: 349182
Page 7588 of 34,919
Β« previous page Β» next page
Filters