8.8

CVSS3.1

CVE-2024-48311 -

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: May 22, 2025, 5:26 p.m.

8.8

CVSS3.1

CVE-2024-51254 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 3:51 p.m.

9.8

CVSS3.1

CVE-2024-51065 -

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: March 31, 2025, 7:29 p.m.

9.8

CVSS3.1

CVE-2024-42835 -

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: March 27, 2026, 3:51 p.m.

8.4

CVSS3.1

CVE-2024-48200 -

An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48307 -

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 7:45 p.m.

6

CVSS3.1

CVE-2024-50802 -

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:36 p.m.

9.8

CVSS3.1

CVE-2024-39332 -

Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: July 10, 2025, 7:35 p.m.

9.9

CVSS3.1

CVE-2024-42515 -

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to aโ€ฆ

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2024-50801 -

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.

๐Ÿ“… Published: Oct. 31, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 4:37 p.m.
Total resulsts: 349182
Page 8079 of 34,919
ยซ previous page ยป next page
Filters