7.5

CVSS3.1

CVE-2024-48196 -

An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 1:15 a.m.

4.8

CVSS3.1

CVE-2024-51507 -

Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 2:55 p.m.

4.8

CVSS3.1

CVE-2024-51508 -

Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 2:57 p.m.

8

CVSS3.1

CVE-2024-48825 -

Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 2:40 p.m.

9.8

CVSS3.1

CVE-2024-48357 -

LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 5:37 p.m.

9.8

CVSS3.1

CVE-2024-48356 -

LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 8:24 p.m.

8.1

CVSS3.1

CVE-2024-48178 -

newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: June 10, 2025, 6:44 p.m.

6.3

CVSS3.1

CVE-2024-48291 -

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 8:34 p.m.

6.5

CVSS3.1

CVE-2024-48107 -

SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 1:19 a.m.

8

CVSS3.1

CVE-2024-48074 -

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.

๐Ÿ“… Published: Oct. 28, 2024, midnight ๐Ÿ”„ Last Modified: May 17, 2025, 2:14 a.m.
Total resulsts: 344670
Page 7677 of 34,467
ยซ previous page ยป next page
Filters