8.8

CVSS3.1

CVE-2024-37869 -

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 8, 2024, 6:15 p.m.

5.4

CVSS3.1

CVE-2024-41515 -

A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

5.4

CVSS3.1

CVE-2024-41513 -

A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

7.5

CVSS3.1

CVE-2024-46078 -

itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 1:02 a.m.

5.4

CVSS3.1

CVE-2024-46077 -

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 5:58 p.m.

8.8

CVSS3.1

CVE-2024-37868 -

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 8, 2024, 6:16 p.m.

3.9

CVSS3.1

CVE-2024-41511 -

A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:41 p.m.

5.4

CVSS3.1

CVE-2024-41514 -

A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: June 2, 2025, 5:40 p.m.

7.2

CVSS3.1

CVE-2024-47910 -

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-47911 -

In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.

๐Ÿ“… Published: Oct. 4, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 4, 2025, 6:38 p.m.
Total resulsts: 349182
Page 8407 of 34,919
ยซ previous page ยป next page
Filters