6.9

CVSS4.0

CVE-2024-6065 - itsourcecode Bakery Online Ordering System index.php sql injection

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument user_email leads to sql injection. The attack may be initiated remotely. The exploit has bee…

πŸ“… Published: June 17, 2024, 9 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

4.8

CVSS4.0

CVE-2024-6064 - GPAC MP4Box loader_xmt.c xmt_node_end use after free

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local access is required to app…

πŸ“… Published: June 17, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

4.8

CVSS4.0

CVE-2024-6063 - GPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereference

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to be approached locall…

πŸ“… Published: June 17, 2024, 8:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

5.9

CVSS3.1

CVE-2024-37893 - MFA bypass in oauth flow in Firefly III

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gain access to Firefly III data using passwords stolen from oth…

πŸ“… Published: June 17, 2024, 7:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-37896 - SQL injection vulnerability in Gin-vue-admin

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerability. The SQL injection vulnerabilities occur when a web application allows users to input data into SQL queries without sufficiently validating or sanitizing the input. Failing t…

πŸ“… Published: June 17, 2024, 7:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2024-6062 - GPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereference

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be app…

πŸ“… Published: June 17, 2024, 7:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

4.8

CVSS4.0

CVE-2024-6061 - GPAC MP4Box isoffin_read.c isoffin_process infinite loop

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is possible to launch the…

πŸ“… Published: June 17, 2024, 7:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

5.7

CVSS3.1

CVE-2024-37895 - API Key Leak in lobe-chat

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request. This issue …

πŸ“… Published: June 17, 2024, 7:28 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 4:08 p.m.

10

CVSS3.1

CVE-2024-37902 - Path thraversal in DeepJavaLibrary

DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model …

πŸ“… Published: June 17, 2024, 7:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2024-6059 - Ingenico Estate Manager News Feed messages cross site scripting

A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages of the component News Feed. The manipulation of the argument message leads to cross site scripting. The attack may be…

πŸ“… Published: June 17, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.
Total resulsts: 347728
Page 9273 of 34,773
Β« previous page Β» next page
Filters