6.9

CVSS4.0

CVE-2024-7279 - SourceCodester Lot Reservation Management System sql injection

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be initiated remote…

πŸ“… Published: July 31, 2024, 12:31 a.m. πŸ”„ Last Modified: Aug. 8, 2024, 1:57 p.m.

8.2

CVSS3.1

CVE-2024-6255 - Path Traversal in gaizhenbiao/chuanhuchatgpt

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation of file paths, enab…

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.1

CVSS4.0

CVE-2024-7278 - itsourcecode Alton Management System team_save.php sql injection

A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_save.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has bee…

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: May 14, 2025, 3:59 p.m.

7.1

CVSS3.1

CVE-2024-41253 -

goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-41258 -

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 2:15 p.m.

6.1

CVSS3.1

CVE-2023-28149 -

An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables.

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2024-42381 -

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occu…

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-41262 -

mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 3:56 p.m.

8.8

CVSS3.1

CVE-2024-40465 -

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2024, 1:11 p.m.

6.3

CVSS3.1

CVE-2024-7264 - ASN.1 date parser overread

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer are…

πŸ“… Published: July 31, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.
Total resulsts: 349182
Page 8993 of 34,919
Β« previous page Β» next page
Filters