7.5

CVSS3.1

CVE-2024-44775 -

kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 3, 2026, 5:16 p.m.

6.6

CVSS3.1

CVE-2024-48622 -

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2024-41344 -

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Aug. 1, 2025, 8:36 p.m.

6.5

CVSS3.1

CVE-2024-48712 -

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.

7.6

CVSS3.1

CVE-2024-48282 -

A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:12 p.m.

9.8

CVSS3.1

CVE-2024-48411 -

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 17, 2025, 1:37 a.m.

4.8

CVSS3.1

CVE-2024-48948 - elliptic: ECDSA signature verification error may reject legitimate transactions

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to va…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2025, 4:16 p.m.

6.5

CVSS3.1

CVE-2024-48714 -

In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.

7.2

CVSS3.1

CVE-2024-9548 - Slimstat Analytics <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attack…

πŸ“… Published: Oct. 14, 2024, 11:29 p.m. πŸ”„ Last Modified: April 8, 2026, 5:34 p.m.

5.3

CVSS3.1

CVE-2024-9546 - WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticat…

πŸ“… Published: Oct. 14, 2024, 11:29 p.m. πŸ”„ Last Modified: April 8, 2026, 5:30 p.m.
Total resulsts: 343996
Page 7778 of 34,400
Β« previous page Β» next page
Filters