9.8

CVSS3.1

CVE-2024-48237 -

WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 7 p.m.

6.5

CVSS3.1

CVE-2024-48236 -

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:09 a.m.

4.9

CVSS3.1

CVE-2024-48232 -

An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read ser…

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 5:33 p.m.

9.8

CVSS3.1

CVE-2024-48204 -

SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 28, 2024, 1:58 p.m.

9.8

CVSS3.1

CVE-2024-37846 -

MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 4:03 p.m.

5.4

CVSS3.1

CVE-2022-30359 -

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, …

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:37 p.m.

6.5

CVSS3.1

CVE-2024-48235 -

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:08 a.m.

8.8

CVSS3.1

CVE-2022-30358 -

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 4:41 p.m.

9.8

CVSS3.1

CVE-2024-48223 -

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:44 p.m.

7.5

CVSS3.1

CVE-2024-48227 -

Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).

πŸ“… Published: Oct. 25, 2024, midnight πŸ”„ Last Modified: Oct. 31, 2024, 3:48 p.m.
Total resulsts: 343921
Page 7624 of 34,393
Β« previous page Β» next page
Filters