6.1

CVSS3.1

CVE-2024-10033 - Aap-gateway: xss on aap-gateway

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions aโ€ฆ

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 6:11 p.m.

6.1

CVSS3.1

CVE-2024-48744 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via "searchinput" POST request parameter.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 5:47 p.m.

7.2

CVSS3.1

CVE-2024-46213 -

REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 12:28 a.m.

6.1

CVSS3.1

CVE-2024-48758 -

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: May 27, 2025, 7:44 p.m.

4.9

CVSS3.1

CVE-2024-46212 -

An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 6:36 p.m.

5.4

CVSS3.1

CVE-2024-46606 -

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: May 22, 2025, 5:25 p.m.

6.1

CVSS3.1

CVE-2024-46605 -

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: May 22, 2025, 5:25 p.m.

5.3

CVSS3.1

CVE-2024-44762 -

A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 15, 2025, 5:55 p.m.

9.8

CVSS3.1

CVE-2024-48180 -

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

๐Ÿ“… Published: Oct. 16, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 5:34 p.m.

4.3

CVSS3.1

CVE-2024-49340 - IBM Watson Studio Local cross-site request forgery

IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

๐Ÿ“… Published: Oct. 15, 2024, 11:57 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 3:06 p.m.
Total resulsts: 343919
Page 7751 of 34,392
ยซ previous page ยป next page
Filters