5.1

CVSS4.0

CVE-2024-8155 - ContiNew Admin tree sql injection

A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseController#tree of the file /api/system/dept/tree?sort=parentId%2Casc&sort=sort%2Casc. The manipulation of the argument sort le…

πŸ“… Published: Aug. 25, 2024, 11 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 1:53 p.m.

5.3

CVSS4.0

CVE-2024-8154 - SourceCodester QR Code Bookmark System Parameter update-bookmark.php cross site scripting

A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_bookmark_id/name/url leads to cross site scripti…

πŸ“… Published: Aug. 25, 2024, 11 p.m. πŸ”„ Last Modified: Aug. 26, 2024, 7:06 p.m.

5.3

CVSS4.0

CVE-2024-8153 - SourceCodester QR Code Bookmark System delete-bookmark.php cross site scripting

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site scripting. The attack may be initiated remot…

πŸ“… Published: Aug. 25, 2024, 10:31 p.m. πŸ”„ Last Modified: Aug. 26, 2024, 7:04 p.m.

5.3

CVSS4.0

CVE-2024-8152 - SourceCodester QR Code Bookmark System Parameter add-bookmark.php cross site scripting

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argument name/url leads to cross site scripting. T…

πŸ“… Published: Aug. 25, 2024, 10:31 p.m. πŸ”„ Last Modified: Aug. 26, 2024, 7:06 p.m.

5.3

CVSS4.0

CVE-2024-8151 - SourceCodester Interactive Map with Marker delete-mark.php cross site scripting

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It is possible to initiate the attack remotely…

πŸ“… Published: Aug. 25, 2024, 10 p.m. πŸ”„ Last Modified: Aug. 26, 2024, 7:07 p.m.

5.1

CVSS4.0

CVE-2024-8150 - ContiNew Admin user sql injection

A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation of the argument sort leads to sql injection.…

πŸ“… Published: Aug. 25, 2024, 10 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 9:01 p.m.

8.8

CVSS4.0

CVE-2024-8158 - User impersonation for lib9p based 9p fileservers

A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any other valid filesystem user. This is due to lib9p not properly verifying that the uname given in the Tauth and Tattach 9p messages matches …

πŸ“… Published: Aug. 25, 2024, 9:31 p.m. πŸ”„ Last Modified: Sept. 12, 2024, 9 p.m.

2

CVSS4.0

CVE-2024-8011 -

Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to Options+ such as Camera.

πŸ“… Published: Aug. 25, 2024, 11:44 a.m. πŸ”„ Last Modified: Sept. 11, 2024, 6:15 p.m.

5.3

CVSS4.0

CVE-2024-8147 - code-projects Pharmacy Management System index.php sql injection

A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php?action=editPharmacist. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploi…

πŸ“… Published: Aug. 25, 2024, 9 a.m. πŸ”„ Last Modified: Sept. 11, 2024, 6:37 p.m.

5.3

CVSS4.0

CVE-2024-8146 - code-projects Pharmacy Management System index.php sql injection

A vulnerability has been found in code-projects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php?action=editSalesman. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploi…

πŸ“… Published: Aug. 25, 2024, 8 a.m. πŸ”„ Last Modified: Sept. 24, 2024, 5 p.m.
Total resulsts: 349182
Page 8741 of 34,919
Β« previous page Β» next page
Filters