9.8

CVSS3.1

CVE-2023-52044 -

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 7:11 p.m.

8.8

CVSS3.1

CVE-2024-48311 -

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 22, 2025, 5:26 p.m.

7.5

CVSS3.1

CVE-2024-39719 -

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file existence on the seโ€ฆ

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 1:32 p.m.

8.8

CVSS3.1

CVE-2024-51254 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

9.8

CVSS3.1

CVE-2024-51065 -

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 7:29 p.m.

9.8

CVSS3.1

CVE-2024-42835 -

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2026, 3:51 p.m.

8.4

CVSS3.1

CVE-2024-48200 -

An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-39722 -

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:24 p.m.

9.8

CVSS3.1

CVE-2024-48307 -

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 7:45 p.m.

6

CVSS3.1

CVE-2024-50802 -

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:36 p.m.
Total resulsts: 345005
Page 7661 of 34,501
ยซ previous page ยป next page
Filters