9.9

CVSS3.1

CVE-2024-4447 -

In the System β†’ Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess "Sign In As" powers, admins who otherwise lack …

πŸ“… Published: July 26, 2024, 2:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7115 - MD-MAFUJUL-HASAN Online-Payroll-Management-System designation_viewmore.php sql injection

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be initiated rem…

πŸ“… Published: July 26, 2024, 2 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

0.0

CVE-2024-7123 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: July 26, 2024, 1:16 a.m. πŸ”„ Last Modified: Aug. 8, 2024, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-7114 - Tianchoy Blog so.php sql injection

A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. The manipulation of the argument search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: July 26, 2024, 1 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

9.8

CVSS3.1

CVE-2024-40117 -

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6…

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-41355 -

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: Feb. 13, 2026, 5:16 p.m.

5.8

CVSS3.1

CVE-2024-42007 -

SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-24257 -

An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-41628 -

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-40433 -

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

πŸ“… Published: July 26, 2024, midnight πŸ”„ Last Modified: Oct. 10, 2025, 3:28 p.m.
Total resulsts: 349182
Page 9050 of 34,919
Β« previous page Β» next page
Filters