5.3

CVSS4.0

CVE-2024-5895 - SourceCodester Employee and Visitor Gate Pass Logging System delete_users sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be …

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.9

CVSS4.0

CVE-2024-5894 - SourceCodester Online Eyewear Shop manage_product.php sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: June 12, 2024, 3 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

7.1

CVSS3.1

CVE-2024-34065 - @strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and…

πŸ“… Published: June 12, 2024, 2:54 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:18 a.m.

5.3

CVSS3.1

CVE-2024-31217 - @strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the application cause it…

πŸ“… Published: June 12, 2024, 2:50 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:13 a.m.

2.3

CVSS3.1

CVE-2024-29181 - @strapi/plugin-content-manager leaks data via relations via the Admin Panel

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. The…

πŸ“… Published: June 12, 2024, 2:46 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:07 a.m.

5.3

CVSS4.0

CVE-2024-5893 - SourceCodester Cab Management System sql injection

A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: June 12, 2024, 2:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.1

CVSS3.1

CVE-2024-37304 - NuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site Scripting

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allo…

πŸ“… Published: June 12, 2024, 2:27 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 7:12 p.m.

9.8

CVSS3.1

CVE-2024-36265 - Apache Submarine Server Core: authorization bypass

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative o…

πŸ“… Published: June 12, 2024, 2:12 p.m. πŸ”„ Last Modified: March 19, 2025, 9:15 p.m.

9.8

CVSS3.1

CVE-2024-36264 - Apache Submarine Commons Utils: default secret

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, w…

πŸ“… Published: June 12, 2024, 2:06 p.m. πŸ”„ Last Modified: March 20, 2025, 7:15 p.m.

8.1

CVSS3.1

CVE-2024-36263 - Apache Submarine Server Core: SQL injection

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we do not plan to release a version that f…

πŸ“… Published: June 12, 2024, 2:05 p.m. πŸ”„ Last Modified: July 15, 2025, 4:38 p.m.
Total resulsts: 347008
Page 9266 of 34,701
Β« previous page Β» next page
Filters