6.4

CVSS3.1

CVE-2024-10621 - Simple Shortcode for Google Maps <= 1.5.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aut…

πŸ“… Published: Nov. 8, 2024, 5:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10993 - Codezips Online Institute Management System manage_website.php unrestricted upload

A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /manage_website.php. The manipulation of the argument website_image leads to unrestricted upload. It is possible to launch the attack remotely…

πŸ“… Published: Nov. 8, 2024, 5:31 a.m. πŸ”„ Last Modified: Nov. 18, 2024, 6:41 p.m.

6.9

CVSS4.0

CVE-2024-10991 - Codezips Hospital Appointment System editBranchResult.php sql injection

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file /editBranchResult.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit …

πŸ“… Published: Nov. 8, 2024, 5 a.m. πŸ”„ Last Modified: Nov. 18, 2024, 6:41 p.m.

8.7

CVSS4.0

CVE-2024-21538 - cross-spawn: regular expression denial of service

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

πŸ“… Published: Nov. 8, 2024, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10990 - SourceCodester Online Veterinary Appointment System view_service.php sql injection

A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/view_service.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The ex…

πŸ“… Published: Nov. 8, 2024, 4:31 a.m. πŸ”„ Last Modified: Nov. 18, 2024, 6:42 p.m.

5.3

CVSS4.0

CVE-2024-10989 - code-projects E-Health Care System detail.php sql injection

A vulnerability classified as critical has been found in code-projects E-Health Care System 1.0. This affects an unknown part of the file /Admin/detail.php. The manipulation of the argument s_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed t…

πŸ“… Published: Nov. 8, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:59 a.m.

6.9

CVSS4.0

CVE-2024-10988 - code-projects E-Health Care System doctor_login.php sql injection

A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Doctor/doctor_login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The expl…

πŸ“… Published: Nov. 8, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:59 a.m.

5.3

CVSS4.0

CVE-2024-10987 - code-projects E-Health Care System user_appointment.php sql injection

A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Doctor/user_appointment.php. The manipulation of the argument schedule_id/schedule_date/schedule_day/start_time/end_time/boo…

πŸ“… Published: Nov. 8, 2024, 3:31 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:58 a.m.

6.5

CVSS3.1

CVE-2024-48010 -

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privilege on the application.

πŸ“… Published: Nov. 8, 2024, 3:01 a.m. πŸ”„ Last Modified: Nov. 26, 2024, 7:26 p.m.

6.8

CVSS3.1

CVE-2024-45759 -

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to unauthorized execution of certain commands to overwrite system co…

πŸ“… Published: Nov. 8, 2024, 2:48 a.m. πŸ”„ Last Modified: Nov. 26, 2024, 2:10 a.m.
Total resulsts: 349182
Page 7981 of 34,919
Β« previous page Β» next page
Filters