9.8
CVE-2024-48229 -
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
6.1
CVE-2024-48448 -
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page.
9.8
CVE-2024-48226 -
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
9.8
CVE-2024-48222 -
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
6.5
CVE-2024-48450 -
An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.
4.3
CVE-2022-30361 -
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal detaiβ¦
9.8
CVE-2022-30357 -
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
7.2
CVE-2024-48700 -
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
9.8
CVE-2024-48579 -
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
6.3
CVE-2024-48343 -
A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.