8.2

CVSS3.1

CVE-2024-36399 - Kanboard affected by Project Takeover via IDOR in ProjectPermissionController

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users t…

πŸ“… Published: June 6, 2024, 3:15 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:22 a.m.

9.8

CVSS3.1

CVE-2024-34832 -

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

πŸ“… Published: June 6, 2024, 2:45 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:53 p.m.

6.3

CVSS3.1

CVE-2024-5684 - ID Charger Connect & Pro - JWT-Null-Algorithm

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would …

πŸ“… Published: June 6, 2024, 12:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

9.8

CVSS3.1

CVE-2024-36779 -

Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.

πŸ“… Published: June 6, 2024, 12:31 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:59 p.m.

10

CVSS3.1

CVE-2024-5675 - Unreliable data deserialization vulnerability in Mentor

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the β€œViewState” field.

πŸ“… Published: June 6, 2024, 12:10 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

4.3

CVSS3.1

CVE-2024-5489 - Wbcom Designs - Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion

The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level a…

πŸ“… Published: June 6, 2024, 11:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-5188 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and…

πŸ“… Published: June 6, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-5038 - Colibri Page Builder <= 1.0.276 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: June 6, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

4.8

CVSS3.1

CVE-2024-5658 - CraftCMS Plugin - Two-Factor Authentication - TOTP Token Stays Valid After Use

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

πŸ“… Published: June 6, 2024, 10:32 a.m. πŸ”„ Last Modified: Sept. 3, 2025, 7:15 a.m.

3.7

CVSS3.1

CVE-2024-5657 - CraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

πŸ“… Published: June 6, 2024, 10:29 a.m. πŸ”„ Last Modified: Sept. 3, 2025, 8:15 a.m.
Total resulsts: 345149
Page 9165 of 34,515
Β« previous page Β» next page
Filters