5.3

CVSS4.0

CVE-2024-10611 - ESAFENET CDG PrintScreenListService.java delProtocol sql injection

A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has…

πŸ“… Published: Nov. 1, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:20 p.m.

5.3

CVSS4.0

CVE-2024-10610 - ESAFENET CDG ProtocolService.java delProtocol sql injection

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The explo…

πŸ“… Published: Nov. 1, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:21 p.m.

5.3

CVSS4.0

CVE-2024-10609 - itsourcecode Tailoring Management System Project typeadd.php sql injection

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection. It is possible to initiate the attack remotely. The exploit has be…

πŸ“… Published: Nov. 1, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:22 p.m.

6.9

CVSS4.0

CVE-2024-10608 - code-projects Courier Management System login.php sql injection

A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: Nov. 1, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 5, 2024, 4:21 p.m.

6.9

CVSS4.0

CVE-2024-10607 - code-projects Courier Management System track-result.php sql injection

A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. The manipulation of the argument Consignment leads to sql injection. The attack can be initiated remotely. The exploit h…

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 4:21 p.m.

4.6

CVSS3.1

CVE-2024-27525 -

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:21 p.m.

7.5

CVSS3.1

CVE-2024-48352 -

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 9:35 p.m.

3.5

CVSS3.1

CVE-2024-22733 -

TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 9:35 p.m.

8.8

CVSS3.1

CVE-2024-48217 -

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-51377 -

An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: Nov. 14, 2024, 11:23 p.m.
Total resulsts: 345148
Page 7667 of 34,515
Β« previous page Β» next page
Filters