5.3

CVSS4.0

CVE-2024-6449 - Arbitrary cross-domain file inclusion in HyperView Geoportal Toolkit

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the…

📅 Published: Aug. 28, 2024, 11:49 a.m. 🔄 Last Modified: Jan. 9, 2025, 5:39 p.m.

5.3

CVSS3.1

CVE-2024-7447 - Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= …

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in all versions up to, and including, 3.7.3.2. …

📅 Published: Aug. 28, 2024, 11:31 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

8.7

CVSS4.0

CVE-2024-7269 - Stored XSS in ConnX ESP HR Management

Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any ans…

📅 Published: Aug. 28, 2024, 10:29 a.m. 🔄 Last Modified: Sept. 19, 2024, 2:37 p.m.

8.3

CVSS3.1

CVE-2024-5546 - SQL Injection

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

📅 Published: Aug. 28, 2024, 8:44 a.m. 🔄 Last Modified: Sept. 19, 2024, 2:39 p.m.

8.8

CVSS3.1

CVE-2023-26322 - GetApps application has code execution vulnerability

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

📅 Published: Aug. 28, 2024, 7:59 a.m. 🔄 Last Modified: Sept. 12, 2024, 5:27 p.m.

7.6

CVSS3.1

CVE-2023-26323 - Xiaomi App Market has a code execution vulnerability

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

📅 Published: Aug. 28, 2024, 7:53 a.m. 🔄 Last Modified: March 2, 2026, 6:27 p.m.

6.3

CVSS3.1

CVE-2023-26321 - The international version of Xiaomi File Manager has a path traversal vulnerability

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.

📅 Published: Aug. 28, 2024, 7:51 a.m. 🔄 Last Modified: March 25, 2025, 4:15 p.m.

8.8

CVSS3.1

CVE-2023-26324 - GetApps application has code execution vulnerability

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

📅 Published: Aug. 28, 2024, 7:28 a.m. 🔄 Last Modified: Sept. 12, 2024, 5:27 p.m.

8.8

CVSS3.1

CVE-2024-45346 - GetApps application has code execution vulnerability

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly…

📅 Published: Aug. 28, 2024, 6:44 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-6311 - Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Upload

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and including, 3.7.3.2. This makes it possible for authenticated attackers, with administrator-level and above permissions, to …

📅 Published: Aug. 28, 2024, 6:43 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.
Total resulsts: 349182
Page 8714 of 34,919
« previous page » next page
Filters