5.3

CVSS4.0

CVE-2024-10071 - ESAFENET CDG EncryptPolicyService.java actionUpdateEncryptPolicyEdit sql injection

A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdateEncryptPolicyEdit of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument encryptPolicyId leads to sql injection. The attack can be in…

πŸ“… Published: Oct. 17, 2024, 4 p.m. πŸ”„ Last Modified: Oct. 22, 2024, 2:20 p.m.

7

CVSS4.0

CVE-2024-9414 - Cross-site Scripting vulnerability in LCDS LAquis SCADA

In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.

πŸ“… Published: Oct. 17, 2024, 3:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2018-25104 - CoinGate Plugin Payment callback.php postProcess logic error

A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors.…

πŸ“… Published: Oct. 17, 2024, 3:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10070 - ESAFENET CDG PolicyPushControlAction.java actionPolicyPush sql injection

A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It is possible to initiate the attack remotely.…

πŸ“… Published: Oct. 17, 2024, 3 p.m. πŸ”„ Last Modified: Oct. 22, 2024, 2:19 p.m.

5.3

CVSS4.0

CVE-2024-10069 - ESAFENET CDG MailDecryptApplicationService.java actionPassMainApplication sql injection

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actionPassMainApplication of the file /com/esafenet/servlet/client/MailDecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be lau…

πŸ“… Published: Oct. 17, 2024, 3 p.m. πŸ”„ Last Modified: Oct. 22, 2024, 2:19 p.m.

5.5

CVSS3.1

CVE-2024-47459 - Substance3D - Sampler | NULL Pointer Dereference (CWE-476)

Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires…

πŸ“… Published: Oct. 17, 2024, 2:59 p.m. πŸ”„ Last Modified: Oct. 23, 2024, 2:17 p.m.

9.1

CVSS3.1

CVE-2024-48920 - PutongOJ: unprivileged users can escalate privileges by constructing requests

PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem…

πŸ“… Published: Oct. 17, 2024, 2:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2005-10003 - mikexstudios Xcomic os command injection

A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability …

πŸ“… Published: Oct. 17, 2024, 2 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 7:35 p.m.

7.2

CVSS3.1

CVE-2024-6333 - Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

πŸ“… Published: Oct. 17, 2024, 1:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-49315 - WordPress FREE DOWNLOAD MANAGER plugin <= 1.0.0 - Arbitrary File Deletion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through <= 1.0.0.

πŸ“… Published: Oct. 17, 2024, 1:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8252 of 34,919
Β« previous page Β» next page
Filters