3.3

CVSS3.1

CVE-2024-24122 -

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart โ€ฆ

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:58 a.m.

8.1

CVSS3.1

CVE-2024-41290 -

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 12:57 a.m.

4.7

CVSS3.1

CVE-2024-45962 -

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 29, 2025, 5:30 p.m.

4.8

CVSS3.1

CVE-2024-45960 -

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: July 3, 2025, 2:30 p.m.

6.4

CVSS3.1

CVE-2024-45965 -

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 13, 2025, 2:50 p.m.

4.8

CVSS3.1

CVE-2024-45964 -

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: July 3, 2025, 2:29 p.m.

9.8

CVSS3.1

CVE-2024-24117 -

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-33662 -

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: May 21, 2025, 6:07 p.m.

10

CVSS3.1

CVE-2024-45519 -

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: Feb. 3, 2026, 7:27 p.m.

5.4

CVSS3.1

CVE-2024-33209 -

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

๐Ÿ“… Published: Oct. 2, 2024, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 4:15 p.m.
Total resulsts: 349182
Page 8422 of 34,919
ยซ previous page ยป next page
Filters