5.3

CVSS4.0

CVE-2024-8295 - FeehiCMS index.php createBanner unrestricted upload

A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The manipulation of the argument BannerForm[img] leads to unrestricted upload. The attack can be initiated r…

πŸ“… Published: Aug. 29, 2024, noon πŸ”„ Last Modified: Aug. 30, 2024, 3:37 p.m.

5.3

CVSS4.0

CVE-2024-8294 - FeehiCMS index.php update unrestricted upload

A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument FriendlyLink[image] leads to unrestricted upload. It is possible to initiate the attack remo…

πŸ“… Published: Aug. 29, 2024, 11 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:38 p.m.

6.4

CVSS3.1

CVE-2024-7895 - Beaver Builder (Lite Version) <= 2.8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜type’ parameter in all versions up to, and including, 2.8.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with C…

πŸ“… Published: Aug. 29, 2024, 10:59 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.

5.3

CVSS3.1

CVE-2024-6551 - GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated atta…

πŸ“… Published: Aug. 29, 2024, 10:59 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

9.8

CVSS3.1

CVE-2024-29723 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categori…

πŸ“… Published: Aug. 29, 2024, 9:46 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:51 p.m.

9.8

CVSS3.1

CVE-2024-29724 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter idDesafio.

πŸ“… Published: Aug. 29, 2024, 9:45 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:50 p.m.

9.8

CVSS3.1

CVE-2024-29725 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list.

πŸ“… Published: Aug. 29, 2024, 9:42 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:50 p.m.

9.8

CVSS3.1

CVE-2024-29726 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/, parameter id.

πŸ“… Published: Aug. 29, 2024, 9:38 a.m. πŸ”„ Last Modified: Sept. 6, 2024, 4:20 p.m.

9.8

CVSS3.1

CVE-2024-29727 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter…

πŸ“… Published: Aug. 29, 2024, 9:36 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:43 p.m.

9.8

CVSS3.1

CVE-2024-29728 - Multiple vulnerabilities in SportsNET

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ , parameter idDesafio.

πŸ“… Published: Aug. 29, 2024, 9:32 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 3:49 p.m.
Total resulsts: 349182
Page 8705 of 34,919
Β« previous page Β» next page
Filters