5.4

CVSS3.1

CVE-2024-48807 -

Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 7:24 p.m.

9.8

CVSS3.1

CVE-2024-48202 -

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:31 a.m.

8.8

CVSS3.1

CVE-2024-51257 -

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.

7.2

CVSS3.1

CVE-2024-48647 -

A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configur…

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: June 27, 2025, 7:49 p.m.

6.1

CVSS3.1

CVE-2024-48346 -

xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-46531 -

phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 4, 2025, 2:35 p.m.

9.8

CVSS3.1

CVE-2024-51424 -

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-51298 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:51 p.m.

8.8

CVSS3.1

CVE-2024-48271 -

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: May 7, 2025, 4:06 p.m.

5.2

CVSS3.1

CVE-2024-31973 -

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.

πŸ“… Published: Oct. 30, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8086 of 34,919
Β« previous page Β» next page
Filters