4.9

CVSS3.1

CVE-2023-5816 - Code Explorer <= 1.4.5 - Authenticated (Admin+) External File Reading

The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only ac…

πŸ“… Published: Oct. 30, 2024, 2:04 a.m. πŸ”„ Last Modified: April 8, 2026, 6:18 p.m.

6.4

CVSS3.1

CVE-2024-9884 - T(-) Countdown <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

πŸ“… Published: Oct. 30, 2024, 2:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10506 - code-projects Blood Bank System B-.php sql injection

A vulnerability classified as critical has been found in code-projects Blood Bank System 1.0. This affects an unknown part of the file /admin/blood/update/B-.php. The manipulation of the argument Bloodname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: Oct. 30, 2024, 2 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2024-10505 - wuzhicms block.php edit code injection

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the pub…

πŸ“… Published: Oct. 30, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 4:38 p.m.

5.3

CVSS4.0

CVE-2024-10503 - Klokan MapTiler tileserver-gl URL cross site scripting

A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argument key leads to cross site scripting. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Oct. 30, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 7, 2024, 3:30 p.m.

5.3

CVSS4.0

CVE-2024-10502 - ESAFENET CDG FileDirectoryService.java getOneFileDirectory sql injection

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function getOneFileDirectory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument directoryId leads to sql injection. The attack can be…

πŸ“… Published: Oct. 30, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 5:20 p.m.

5.3

CVSS4.0

CVE-2024-10501 - ESAFENET CDG ExamCDGDocService.java findById sql injection

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 5:20 p.m.

5.3

CVSS4.0

CVE-2024-10500 - ESAFENET CDG HookWhiteListService.java sql injection

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched …

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 9:02 p.m.

8

CVSS3.1

CVE-2024-48093 -

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-31972 -

EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulnerable fields this way are executed immediate…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8085 of 34,919
Β« previous page Β» next page
Filters