7.5

CVSS3.1

CVE-2024-48352 -

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 9:35 p.m.

4.6

CVSS3.1

CVE-2024-27525 -

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.

πŸ“… Published: Nov. 1, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:21 p.m.

6.9

CVSS4.0

CVE-2024-10605 - code-projects Blood Bank Management System request.php cross-site request forgery

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /file/request.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: Oct. 31, 2024, 11:31 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2024-10602 - Tongda OA 2017 data_picker_link.php sql injection

A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/list/input_form/data_picker_link.php. The manipulation of the argument dataSrc leads to sql injection. The attack may be launch…

πŸ“… Published: Oct. 31, 2024, 11:31 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:46 p.m.

5.3

CVSS4.0

CVE-2024-10601 - Tongda OA 2017 delete.php sql injection

A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /general/address/private/address/query/delete.php. The manipulation of the argument where_repeat leads to sql injection. The attack can be …

πŸ“… Published: Oct. 31, 2024, 11 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:45 p.m.

6.9

CVSS4.0

CVE-2024-10600 - Tongda OA 2017 submenu.php sql injection

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. The manipulation of the argument appid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclos…

πŸ“… Published: Oct. 31, 2024, 11 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:45 p.m.

6.9

CVSS4.0

CVE-2024-10599 - Tongda OA 2017 package_static_resources.php resource consumption

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the file /inc/package_static_resources.php. The manipulation leads to resource consumption. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Oct. 31, 2024, 9:31 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:44 p.m.

6.9

CVSS4.0

CVE-2024-10598 - Tongda OA Annual Leave data.php improper authorization

A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization. The attack can be initiat…

πŸ“… Published: Oct. 31, 2024, 9:31 p.m. πŸ”„ Last Modified: Nov. 4, 2024, 7:44 p.m.

6.5

CVSS3.1

CVE-2024-6479 - SIP Reviews Shortcode for WooCommerce <= 1.2.3 - Authenticated (Contributor+) SQL Injection

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient prepara…

πŸ“… Published: Oct. 31, 2024, 9:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-6480 - SIP Reviews Shortcode for WooCommerce <= 1.2.3 - Authenticated (Contributor+) Cross-Site Scripting

The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied …

πŸ“… Published: Oct. 31, 2024, 9:30 p.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.
Total resulsts: 349182
Page 8073 of 34,919
Β« previous page Β» next page
Filters