5.4

CVSS3.1

CVE-2024-48706 -

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

5.3

CVSS3.1

CVE-2024-45526 -

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to degrade gradually.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS3.1

CVE-2024-49210 -

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web applicat…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 7:35 p.m.

7.5

CVSS3.1

CVE-2024-48570 -

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 6:59 p.m.

9.8

CVSS3.1

CVE-2024-46483 -

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-48644 -

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, suc…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-44331 - gstreamer1-rtsp-server: DoS via rtsp-media.c

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-46482 -

An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-48656 -

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 24, 2024, 2:37 p.m.

4.8

CVSS3.1

CVE-2024-48652 -

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 4:51 p.m.
Total resulsts: 349182
Page 8180 of 34,919
Β« previous page Β» next page
Filters