5.3

CVSS4.0

CVE-2024-7327 - Xinhu RockOA openmodhetongAction.php dataAction sql injection

A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php. The manipulation of the argument nickName leads to sql injection. The attack can be initiated remotely. The exploit h…

πŸ“… Published: July 31, 2024, 10 p.m. πŸ”„ Last Modified: Aug. 23, 2024, 4:41 p.m.

8.5

CVSS4.0

CVE-2024-7326 - IObit DualSafe Password Manager BPL RTL120.BPL uncontrolled search path

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The ident…

πŸ“… Published: July 31, 2024, 8:31 p.m. πŸ”„ Last Modified: Aug. 15, 2024, 7:03 p.m.

5.5

CVSS3.1

CVE-2017-3772 -

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

πŸ“… Published: July 31, 2024, 8:30 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:05 p.m.

7.8

CVSS3.1

CVE-2019-6197 -

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

πŸ“… Published: July 31, 2024, 8:30 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:06 p.m.

7.8

CVSS3.1

CVE-2019-6198 -

A vulnerability was reported in Lenovo PC Manager prior to versionΒ 2.8.90.11211 that could allow a local attacker to escalate privileges.

πŸ“… Published: July 31, 2024, 8:30 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:07 p.m.

7.3

CVSS3.1

CVE-2022-4001 -

An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

πŸ“… Published: July 31, 2024, 8:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2022-4002 -

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

πŸ“… Published: July 31, 2024, 8:29 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:23 p.m.

2.7

CVSS3.1

CVE-2022-4003 -

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

πŸ“… Published: July 31, 2024, 8:29 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:23 p.m.

7.8

CVSS3.1

CVE-2023-1577 -

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.

πŸ“… Published: July 31, 2024, 8:29 p.m. πŸ”„ Last Modified: Aug. 13, 2024, 3:12 p.m.

2.1

CVSS4.0

CVE-2024-4187 - Stored XSS vulnerability has been discovered in OpenTextβ„’ Filr. The vulnerability could cause users…

Stored XSS vulnerability has been discovered in OpenTextβ„’ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

πŸ“… Published: July 31, 2024, 8:28 p.m. πŸ”„ Last Modified: Aug. 15, 2024, 2:45 p.m.
Total resulsts: 349182
Page 8984 of 34,919
Β« previous page Β» next page
Filters