5.3

CVSS4.0

CVE-2024-6801 - SourceCodester Online Student Management System add-students.php unrestricted upload

A vulnerability, which was classified as critical, has been found in SourceCodester Online Student Management System 1.0. This issue affects some unknown processing of the file /add-students.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remote…

πŸ“… Published: July 17, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

3

CVSS3.1

CVE-2024-6595 - Uncontrolled Search Path Element in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

πŸ“… Published: July 17, 2024, 1:30 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

8.8

CVSS3.1

CVE-2024-40119 -

Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover.

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-41009 - bpf: Fix overrunning reservations in ringbuf

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is implemented as a power-of-2 sized circular buffer, with two logical and ever-increasing counters: consumer_pos is the consumer counter to show which l…

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

6.3

CVSS3.1

CVE-2024-40402 -

A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: April 23, 2025, 2:19 p.m.

6.1

CVSS3.1

CVE-2023-43971 -

Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 6:15 p.m.

8.1

CVSS3.1

CVE-2024-38447 -

NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:09 p.m.

5.5

CVSS3.1

CVE-2024-41010 - bpf: Fix too early release of tcx_entry

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported an issue that the tcx_entry can be released too early leading to a use after free (UAF) when an active old-style …

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:20 a.m.

6.5

CVSS3.1

CVE-2024-38446 -

NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:09 p.m.

5.4

CVSS3.1

CVE-2024-39125 -

Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

πŸ“… Published: July 17, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 6:15 p.m.
Total resulsts: 349182
Page 9118 of 34,919
Β« previous page Β» next page
Filters