5.3

CVSS4.0

CVE-2024-7190 - itsourcecode Society Management System get_price.php sql injection

A vulnerability classified as critical was found in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/get_price.php. The manipulation of the argument expenses_id leads to sql injection. The attack can be launched remotely. The …

πŸ“… Published: July 29, 2024, 8 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

5.3

CVSS4.0

CVE-2024-7189 - itsourcecode Online Food Ordering System editproduct.php unrestricted upload

A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been…

πŸ“… Published: July 29, 2024, 7:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

6.9

CVSS4.0

CVE-2024-7188 - Bylancer Quicklancer GET Parameter listing sql injection

A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exp…

πŸ“… Published: July 29, 2024, 7 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

8.7

CVSS4.0

CVE-2024-7187 - TOTOLINK A3600R cstecgi.cgi UploadCustomModule buffer overflow

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. T…

πŸ“… Published: July 29, 2024, 6:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

8.7

CVSS4.0

CVE-2024-7186 - TOTOLINK A3600R cstecgi.cgi setWiFiAclAddConfig buffer overflow

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. This affects the function setWiFiAclAddConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument comment leads to buffer overflow. It is possible to initiate the attack remotely.…

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

5.9

CVSS3.1

CVE-2024-6487 - Inline Related Posts < 3.8.0 - Admin+ Stored XSS

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: May 30, 2025, 4:55 p.m.

9.1

CVSS3.1

CVE-2024-6366 - User Profile Builder < 3.11.8 - Unauthenticated Media Upload

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: May 30, 2025, 4:55 p.m.

4.6

CVSS3.1

CVE-2024-6362 - Ultimate Blocks < 3.2.0 - Contributor+ Stored XSS

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: May 29, 2025, 5:34 p.m.

4.7

CVSS3.1

CVE-2024-5883 - Ultimate Classified Listings < 1.3 - Reflected XSS

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: April 10, 2025, 1:50 p.m.

7.5

CVSS3.1

CVE-2024-5882 - Ultimate Classified Listings < 1.3 - Unauthenticated LFI

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

πŸ“… Published: July 29, 2024, 6 a.m. πŸ”„ Last Modified: April 10, 2025, 1:52 p.m.
Total resulsts: 349182
Page 9023 of 34,919
Β« previous page Β» next page
Filters