9.8

CVSS3.1

CVE-2024-48580 -

SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: May 2, 2025, 7:51 p.m.

7.5

CVSS3.1

CVE-2022-30354 -

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 23, 2025, 12:42 a.m.

4.8

CVSS3.1

CVE-2024-48233 -

mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 5:33 p.m.

9.8

CVSS3.1

CVE-2024-37847 -

An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 3:47 p.m.

9.8

CVSS3.1

CVE-2024-48428 -

An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 7:15 p.m.

4.9

CVSS3.1

CVE-2024-48234 -

An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (SSRF) vulnerability that can read server fil…

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 7:35 p.m.

6.1

CVSS3.1

CVE-2024-48396 -

AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 8:35 p.m.

5.3

CVSS3.1

CVE-2023-26248 -

The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor con…

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 1:58 p.m.

6.5

CVSS3.1

CVE-2024-48743 -

Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:39 p.m.

9.8

CVSS3.1

CVE-2024-48581 -

File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 9:12 p.m.
Total resulsts: 343921
Page 7622 of 34,393
Β« previous page Β» next page
Filters