5.3

CVSS4.0

CVE-2024-10137 - code-projects Pharmacy Management System manage_medicine.php sql injection

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /manage_medicine.php?action=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The โ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 12:31 p.m. ๐Ÿ”„ Last Modified: Oct. 22, 2024, 2:17 p.m.

5.3

CVSS4.0

CVE-2024-10136 - code-projects Pharmacy Management System manage_invoice.php sql injection

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. The attack can be initiated remotely. The expโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, noon ๐Ÿ”„ Last Modified: Oct. 22, 2024, 2:15 p.m.

5.3

CVSS4.0

CVE-2024-10135 - ESAFENET CDG NetSecConfigService.java actionDelNetSecConfig sql injection

A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects the function actionDelNetSecConfig of the file /com/esafenet/servlet/netSec/NetSecConfigService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 11:31 a.m. ๐Ÿ”„ Last Modified: Oct. 22, 2024, 6:09 p.m.

5.3

CVSS4.0

CVE-2024-10134 - ESAFENET CDG MultiServerAjax.java connectLogout sql injection

A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The manipulation of the argument servername leads to sql injection. The attack may be launched remotely. The explโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 10 a.m. ๐Ÿ”„ Last Modified: Oct. 22, 2024, 6:10 p.m.

6.4

CVSS3.1

CVE-2024-9897 - StreamWeasels Twitch Integration <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scriptinโ€ฆ

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-twitch-embed shortcode in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiblโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 9:37 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:25 p.m.

5.3

CVSS4.0

CVE-2024-10133 - ESAFENET CDG NetSecPolicyAjax.java updateNetSecPolicyPriority sql injection

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. Affected by this vulnerability is the function updateNetSecPolicyPriority of the file /com/esafenet/servlet/ajax/NetSecPolicyAjax.java. The manipulation of the argument id/frontId leads to sql injection. The attack can be โ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 8:31 a.m. ๐Ÿ”„ Last Modified: Oct. 22, 2024, 6:10 p.m.

4.3

CVSS3.1

CVE-2024-9889 - ElementInvader Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Information Exposure

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/pasโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 6:42 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 p.m.

4.3

CVSS3.1

CVE-2023-6243 - EventON PRO - WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admโ€ฆ

The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. This makes it possible for unauthenticated aโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 6:41 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2024-21536 - http-proxy-middleware: Denial of Service

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.

๐Ÿ“… Published: Oct. 19, 2024, 5 a.m. ๐Ÿ”„ Last Modified: Nov. 1, 2024, 6:03 p.m.

8.8

CVSS3.1

CVE-2024-10131 - Remote Code Execution in infiniflow/ragflow

The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from various model dictionaries. This approach allowsโ€ฆ

๐Ÿ“… Published: Oct. 19, 2024, 3:50 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 8235 of 34,919
ยซ previous page ยป next page
Filters