7.2

CVSS3.1

CVE-2024-37845 -

MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2024, 9:53 p.m.

6.1

CVSS3.1

CVE-2024-48654 -

Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2024, 1:58 p.m.

5.4

CVSS3.1

CVE-2022-30360 -

OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 4:38 p.m.

4.8

CVSS3.1

CVE-2024-48239 -

An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 6:56 p.m.

9.8

CVSS3.1

CVE-2024-48230 -

funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 3:57 p.m.

9.1

CVSS3.1

CVE-2024-48225 -

Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 3:35 p.m.

7.5

CVSS3.1

CVE-2024-48224 -

Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 3:32 p.m.

9.8

CVSS3.1

CVE-2024-48218 -

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2024, 3:44 p.m.

9.8

CVSS3.1

CVE-2024-48580 -

SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:51 p.m.

7.5

CVSS3.1

CVE-2022-30354 -

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.

๐Ÿ“… Published: Oct. 25, 2024, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 12:42 a.m.
Total resulsts: 343919
Page 7621 of 34,392
ยซ previous page ยป next page
Filters