9.8

CVSS3.1

CVE-2024-48229 -

funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:49 p.m.

6.1

CVSS3.1

CVE-2024-48448 -

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 9:35 p.m.

9.8

CVSS3.1

CVE-2024-48226 -

Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:38 p.m.

9.8

CVSS3.1

CVE-2024-48222 -

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:44 p.m.

6.5

CVSS3.1

CVE-2024-48450 -

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 29, 2024, 9:35 p.m.

4.3

CVSS3.1

CVE-2022-30361 -

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal detai…

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:34 p.m.

9.8

CVSS3.1

CVE-2022-30357 -

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:43 p.m.

7.2

CVSS3.1

CVE-2024-48700 -

Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 3:40 p.m.

9.8

CVSS3.1

CVE-2024-48579 -

SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 5:39 p.m.

6.3

CVSS3.1

CVE-2024-48343 -

A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: May 28, 2025, 9:06 p.m.
Total resulsts: 343921
Page 7623 of 34,393
Β« previous page Β» next page
Filters