8.8

CVSS3.1

CVE-2024-40474 -

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2024, 1:40 p.m.

5.4

CVSS3.1

CVE-2024-40473 -

A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Sept. 3, 2024, 7:35 p.m.

8.8

CVSS3.1

CVE-2024-40476 -

A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete Tenant action at th…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2024, 1:43 p.m.

7.5

CVSS3.1

CVE-2024-6893 - Journyx Unauthenticated XML External Entities Injection

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

πŸ“… Published: Aug. 7, 2024, 11:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

6.1

CVSS3.1

CVE-2024-6892 - Journyx Reflected Cross Site Scripting

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

πŸ“… Published: Aug. 7, 2024, 11:19 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

8.8

CVSS3.1

CVE-2024-6891 - Journyx Authenticated Remote Code Execution

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

πŸ“… Published: Aug. 7, 2024, 11:13 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

8.8

CVSS3.1

CVE-2024-6890 - Journyx Unauthenticated Password Reset Bruteforce

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

πŸ“… Published: Aug. 7, 2024, 11:09 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

7.5

CVSS3.1

CVE-2024-6707 - Open WebUI Arbitrary File Upload + Path Traversal

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

πŸ“… Published: Aug. 7, 2024, 11:04 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

6.3

CVSS3.1

CVE-2024-6706 - Open WebUI Stored Cross-Site Scripting

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

πŸ“… Published: Aug. 7, 2024, 11:01 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

9.8

CVSS3.1

CVE-2024-41912 -

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.

πŸ“… Published: Aug. 7, 2024, 7:54 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 5:37 p.m.
Total resulsts: 349182
Page 8922 of 34,919
Β« previous page Β» next page
Filters