5.3

CVSS4.0

CVE-2024-8170 - SourceCodester Zipped Folder Manager App add-folder.php unrestricted upload

A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /endpoint/add-folder.php. The manipulation of the argument folder leads to unrestricted upload. It is possible to initiate the attack remotely. The expl…

📅 Published: Aug. 26, 2024, 3:31 p.m. 🔄 Last Modified: Aug. 27, 2024, 4:02 p.m.

5.9

CVSS3.1

CVE-2024-43967 - WordPress WP Testimonial Widget plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.

📅 Published: Aug. 26, 2024, 3:12 p.m. 🔄 Last Modified: Nov. 8, 2024, 8:35 a.m.

7.6

CVSS3.1

CVE-2024-43966 - WordPress WP Testimonial Widget plugin <= 3.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.

📅 Published: Aug. 26, 2024, 3:07 p.m. 🔄 Last Modified: Nov. 8, 2024, 8:34 a.m.

6.9

CVSS4.0

CVE-2024-8169 - code-projects Online Quiz Site signupuser.php sql injection

A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be launched remotely. The exploit has been dis…

📅 Published: Aug. 26, 2024, 3 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2024-8168 - code-projects Online Bus Reservation Site login.php sql injection

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The …

📅 Published: Aug. 26, 2024, 3 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

9.3

CVSS4.0

CVE-2024-7988 - ThinManager® ThinServer™ Information Disclosure and Remote Code Execution Vulnerabilities

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

📅 Published: Aug. 26, 2024, 2:47 p.m. 🔄 Last Modified: Oct. 21, 2025, 6:58 p.m.

8.5

CVSS4.0

CVE-2024-7987 - Rockwell Automation ThinManager® ThinServer™ Information Disclosure and Remote Code Execution Vulne…

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to uplo…

📅 Published: Aug. 26, 2024, 2:40 p.m. 🔄 Last Modified: Oct. 21, 2025, 6:58 p.m.

6.9

CVSS4.0

CVE-2024-8167 - code-projects Job Portal forget.php sql injection

A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed …

📅 Published: Aug. 26, 2024, 2:31 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

5.1

CVSS4.0

CVE-2024-8166 - Ruijie EG2000K index.php unrestricted upload

A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknown code of the file /tool/index.php?c=download&a=save. The manipulation of the argument content leads to unrestricted upload. The attack can be initiated remotely. The exploit has …

📅 Published: Aug. 26, 2024, 2:31 p.m. 🔄 Last Modified: Aug. 27, 2024, 1:03 p.m.

4.8

CVSS4.0

CVE-2024-38859 - XSS in view page with SLA column

XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts could be executed when the view page was cloned by o…

📅 Published: Aug. 26, 2024, 2:15 p.m. 🔄 Last Modified: Dec. 3, 2024, 5:47 p.m.
Total resulsts: 347734
Page 8586 of 34,774
« previous page » next page
Filters