4.9

CVSS3.1

CVE-2024-45894 -

BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: April 23, 2025, 1:05 a.m.

6.6

CVSS3.1

CVE-2024-45933 -

OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-28709 -

Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

5.7

CVSS3.1

CVE-2024-44674 -

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 2:51 p.m.

5.5

CVSS3.1

CVE-2024-46325 -

TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: June 2, 2025, 5:35 p.m.

9.8

CVSS3.1

CVE-2024-45873 -

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-46300 -

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2024, 6:52 p.m.

6.5

CVSS3.1

CVE-2024-45919 -

A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to unauthorized access to sensitive information or…

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: July 3, 2025, 1:48 p.m.

9.1

CVSS3.1

CVE-2024-46446 -

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: Oct. 11, 2024, 1:04 p.m.

8.1

CVSS3.1

CVE-2024-8926 - PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,Β when using a certain non-standard configurations of Windows codepages, the fixes forΒ  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3 Β may still be bypassed and the same command injection related to Windo…

πŸ“… Published: Oct. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.
Total resulsts: 349182
Page 8381 of 34,919
Β« previous page Β» next page
Filters