5.3

CVSS4.0

CVE-2024-4725 - Campcodes Legal Case Management System client_user cross site scripting

A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/client_user. The manipulation of the argument f_name leads to cross site scripting. The attack can be launched re…

πŸ“… Published: May 10, 2024, 5 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:33 p.m.

6.8

CVSS3.1

CVE-2024-27269 - IBM QRadar SIEM information disclosure

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.

πŸ“… Published: May 10, 2024, 4:58 p.m. πŸ”„ Last Modified: July 25, 2025, 9:05 p.m.

7.5

CVSS3.1

CVE-2024-33818 -

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

πŸ“… Published: May 10, 2024, 4:39 p.m. πŸ”„ Last Modified: March 27, 2025, 4:15 p.m.

5.3

CVSS4.0

CVE-2024-4724 - Campcodes Legal Case Management System case-type cross site scripting

A vulnerability, which was classified as problematic, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/case-type. The manipulation of the argument case_type_name leads to cross site scripting. It is possible to launch the attack remotely. T…

πŸ“… Published: May 10, 2024, 4:31 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:33 p.m.

5.3

CVSS4.0

CVE-2024-4723 - Campcodes Legal Case Management System case-status cross site scripting

A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. This issue affects some unknown processing of the file /admin/case-status. The manipulation of the argument case_status leads to cross site scripting. The attack may be initiated remo…

πŸ“… Published: May 10, 2024, 4:31 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:33 p.m.

8.6

CVSS3.1

CVE-2024-34199 -

TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.

πŸ“… Published: May 10, 2024, 4:24 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 4:15 p.m.

6.5

CVSS3.1

CVE-2024-34245 -

An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.

πŸ“… Published: May 10, 2024, 4:19 p.m. πŸ”„ Last Modified: April 1, 2025, 6:05 p.m.

8.6

CVSS3.1

CVE-2023-26566 -

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.

πŸ“… Published: May 10, 2024, 4:14 p.m. πŸ”„ Last Modified: July 13, 2025, 11:15 a.m.

5.3

CVSS4.0

CVE-2024-4722 - Campcodes Complete Web-Based School Management System index.php cross site scripting

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument category leads to cross site scripting. The attack can be initiated remotely. The exploit…

πŸ“… Published: May 10, 2024, 4 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 8:55 p.m.

6.3

CVSS3.1

CVE-2024-34695 - WOWS Karma vulnerable to a post submission bounce/timing attack

WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests…

πŸ“… Published: May 10, 2024, 3:57 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.
Total resulsts: 343975
Page 9386 of 34,398
Β« previous page Β» next page
Filters