4.3

CVSS3.1

CVE-2024-48783 -

An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: Dec. 4, 2024, 3:15 p.m.

5.1

CVSS3.1

CVE-2024-44337 - gomarkdown/markdown: infinite loop via the paragraph function of parser/block.go

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of th…

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48283 -

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 4, 2025, 2:36 p.m.

9.8

CVSS3.1

CVE-2024-48781 -

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-48710 -

In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 8:27 p.m.

8.1

CVSS3.1

CVE-2024-41311 -

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 24, 2025, 2:41 p.m.

5.3

CVSS3.1

CVE-2024-48624 -

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 6:02 p.m.

7.6

CVSS3.1

CVE-2024-48279 -

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:19 p.m.

7.6

CVSS3.1

CVE-2024-48280 -

A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 5:18 p.m.

9.8

CVSS3.1

CVE-2024-48779 -

An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.

πŸ“… Published: Oct. 15, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8295 of 34,919
Β« previous page Β» next page
Filters