8.8

CVSS3.1

CVE-2024-24409 - Privilege Escalation

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable toย Privilege Escalation in theย Modify Computers option.

๐Ÿ“… Published: Nov. 8, 2024, 8:01 a.m. ๐Ÿ”„ Last Modified: Nov. 13, 2024, 8:35 p.m.

5.1

CVSS4.0

CVE-2024-11000 - CodeAstro Real Estate Management System About Us Page aboutedit.php unrestricted upload

A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. The attack โ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 8 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 6:10 p.m.

5.1

CVSS4.0

CVE-2024-10999 - CodeAstro Real Estate Management System About Us Page aboutadd.php unrestricted upload

A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible to launch the attacโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 8 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 6:10 p.m.

6.9

CVSS4.0

CVE-2024-10998 - 1000 Projects Bookstore Management System process_category_add.php sql injection

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/process_category_add.php. The manipulation of the argument cat leads to sql injection. The attack may be initiated remotely. The eโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 7:31 a.m. ๐Ÿ”„ Last Modified: March 23, 2026, 4:33 p.m.

5.3

CVSS4.0

CVE-2024-10997 - 1000 Projects Bookstore Management System book_list.php sql injection

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /book_list.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been diโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 7 a.m. ๐Ÿ”„ Last Modified: March 23, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2024-10269 - Easy SVG Support <= 3.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access andโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 6:39 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:56 p.m.

6.9

CVSS4.0

CVE-2024-10996 - 1000 Projects Bookstore Management System process_category_edit.php sql injection

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/process_category_edit.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. Theโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 6:31 a.m. ๐Ÿ”„ Last Modified: March 23, 2026, 4:33 p.m.

6.9

CVSS4.0

CVE-2024-10995 - Codezips Hospital Appointment System removeDoctorResult.php sql injection

A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /removeDoctorResult.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit โ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 6:31 a.m. ๐Ÿ”„ Last Modified: Nov. 13, 2024, 1 a.m.

5.3

CVSS4.0

CVE-2024-10994 - Codezips Online Institute Management System edit_user.php unrestricted upload

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit_user.php. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remoteโ€ฆ

๐Ÿ“… Published: Nov. 8, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 6:41 p.m.

9.6

CVSS3.1

CVE-2024-7982 - Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS

The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

๐Ÿ“… Published: Nov. 8, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 4:42 p.m.
Total resulsts: 349182
Page 7980 of 34,919
ยซ previous page ยป next page
Filters