7.5

CVSS3.1

CVE-2024-38429 - Matrix - CWE-552: Files or Directories Accessible to External Parties

Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

📅 Published: July 30, 2024, 8:45 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:25 a.m.

6.4

CVSS3.1

CVE-2024-40895 -

FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executab…

📅 Published: July 30, 2024, 8:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7225 - SourceCodester Insurance Management System Edit Insurance Policy Page update_policy cross site scri…

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy of the component Edit Insurance Policy Page. The manipulation of the argument pname leads to cross site scrip…

📅 Published: July 30, 2024, 8:31 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:51 a.m.

6.1

CVSS3.1

CVE-2024-41693 - Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

📅 Published: July 30, 2024, 8:28 a.m. 🔄 Last Modified: May 19, 2025, 12:38 p.m.

9.1

CVSS3.1

CVE-2023-48396 - Apache SeaTunnel Web: Authentication bypass

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects…

📅 Published: July 30, 2024, 8:15 a.m. 🔄 Last Modified: July 10, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2024-7224 - SourceCodester Lot Reservation Management System lot_details.php sql injection

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /lot_details.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The explo…

📅 Published: July 30, 2024, 8 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:51 a.m.

5.3

CVSS4.0

CVE-2024-7223 - SourceCodester Lot Reservation Management System view_model.php sql injection

A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_model.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.…

📅 Published: July 30, 2024, 7:31 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:51 a.m.

5.3

CVSS4.0

CVE-2024-7222 - SourceCodester Lot Reservation Management System home.php sql injection

A vulnerability, which was classified as critical, was found in SourceCodester Lot Reservation Management System 1.0. Affected is an unknown function of the file /home.php. The manipulation of the argument type leads to sql injection. It is possible to launch the attack remotely. The exploit has be…

📅 Published: July 30, 2024, 7 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:51 a.m.

6.4

CVSS3.1

CVE-2024-7100 - Bold Page Builder <= 5.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_but…

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_button shortcode in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: July 30, 2024, 6:48 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

5.3

CVSS4.0

CVE-2024-7221 - SourceCodester/Campcodes School Log Management System manage_user.php sql injection

A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown part of the file /admin/manage_user.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and …

📅 Published: July 30, 2024, 6:31 a.m. 🔄 Last Modified: Sept. 29, 2025, 9:07 p.m.
Total resulsts: 346541
Page 8735 of 34,655
« previous page » next page
Filters