7.5

CVSS3.1

CVE-2024-40407 -

A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 2:24 p.m.

4.8

CVSS3.1

CVE-2024-40410 -

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 2:24 p.m.

7.5

CVSS3.1

CVE-2024-50955 -

An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2023-38920 -

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 5:53 p.m.

6.5

CVSS3.1

CVE-2024-45876 -

The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for manipulation of SQL queries.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-50972 -

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2024, 8:35 p.m.

8.8

CVSS3.1

CVE-2024-50854 -

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 5:15 p.m.

8.1

CVSS3.1

CVE-2024-40405 -

Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 2:24 p.m.

6.1

CVSS3.1

CVE-2024-50969 -

A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:45 a.m.

5.4

CVSS3.1

CVE-2024-45875 -

The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.

๐Ÿ“… Published: Nov. 13, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7908 of 34,919
ยซ previous page ยป next page
Filters