6.5

CVSS3.1

CVE-2024-48235 -

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:08 a.m.

8.8

CVSS3.1

CVE-2022-30358 -

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:41 p.m.

9.8

CVSS3.1

CVE-2024-48223 -

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:44 p.m.

7.5

CVSS3.1

CVE-2024-48227 -

Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:48 p.m.

6.1

CVSS3.1

CVE-2024-48228 -

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 6:46 p.m.

8.8

CVSS3.1

CVE-2022-30356 -

OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:31 p.m.

8.8

CVSS3.1

CVE-2024-48655 -

An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 8:44 p.m.

4.7

CVSS3.1

CVE-2024-48238 -

WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 6:59 p.m.

9.8

CVSS3.1

CVE-2022-30355 -

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 5:31 p.m.

5.3

CVSS4.0

CVE-2024-10353 - SourceCodester Online Exam System admin-dashboard access control

A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the publi…

πŸ“… Published: Oct. 24, 2024, 11:31 p.m. πŸ”„ Last Modified: Oct. 30, 2024, 4:21 p.m.
Total resulsts: 343825
Page 7615 of 34,383
Β« previous page Β» next page
Filters