5.3

CVSS4.0

CVE-2024-51488 - Insufficient Validation in Delete Message in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to delete messages to any use…

πŸ“… Published: Nov. 11, 2024, 7:42 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 8:12 p.m.

5.3

CVSS4.0

CVE-2024-51489 - Insufficient Message Token Validation in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to send messages…

πŸ“… Published: Nov. 11, 2024, 7:37 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 8:12 p.m.

5.5

CVSS3.1

CVE-2024-51490 - Stored Cross-Site Scripting in Ampache

Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This …

πŸ“… Published: Nov. 11, 2024, 7:35 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 8:13 p.m.

5.3

CVSS4.0

CVE-2024-11078 - code-projects Job Recruitment register.php cross site scripting

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e/role leads to cross site scripting. The attack can be launched remotely. The ex…

πŸ“… Published: Nov. 11, 2024, 7:31 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 2:26 p.m.

9.1

CVSS3.1

CVE-2024-51747 - Arbitrary File Read and Delete in kanboard

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLi…

πŸ“… Published: Nov. 11, 2024, 7:22 p.m. πŸ”„ Last Modified: Nov. 12, 2024, 1:55 p.m.

9.1

CVSS3.1

CVE-2024-51748 - Remote code execution through language setting in kanboard

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `s…

πŸ“… Published: Nov. 11, 2024, 7:20 p.m. πŸ”„ Last Modified: Nov. 12, 2024, 2:44 p.m.

4.1

CVSS3.1

CVE-2024-51992 - Method Exposure Vulnerability in Modals in orchid/platform

Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue (CWE-749: Exposed Dangerous Method or Function) in the Orchid Platform’s asynchronous modal functionality, affecti…

πŸ“… Published: Nov. 11, 2024, 7:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2024-52286 - Self Cross Site Scripting (XSS) In Merge Functionality in Stirling-PDF

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted user input (file name) and uses it directly in the creation of HTML pages allowing any unauthenticated to execute JavaScript code…

πŸ“… Published: Nov. 11, 2024, 7:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-11086 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Nov. 11, 2024, 7:13 p.m. πŸ”„ Last Modified: Nov. 20, 2024, 1:15 p.m.

6.9

CVSS4.0

CVE-2024-10315 - Insecure Configuration in Gliffy Online

In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.

πŸ“… Published: Nov. 11, 2024, 7:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7943 of 34,919
Β« previous page Β» next page
Filters