8.2

CVSS3.1

CVE-2024-34360 - Previous ATX is not checked to be the newest valid ATX by Smesher when validating incoming ATX

go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX ever published by an i…

πŸ“… Published: May 10, 2024, 3:50 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:18 a.m.

5.4

CVSS3.1

CVE-2024-28781 - IBM UrbanCode Deploy cross-site scripting

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p…

πŸ“… Published: May 10, 2024, 3:49 p.m. πŸ”„ Last Modified: Jan. 27, 2025, 6:31 p.m.

5.3

CVSS4.0

CVE-2024-4721 - Campcodes Complete Web-Based School Management System add_student_subject.php cross site scripting

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/add_student_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to initiate the attack…

πŸ“… Published: May 10, 2024, 3:31 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 8:50 p.m.

4.8

CVSS3.1

CVE-2024-34349 - Sylius potentially vulnerable to Cross Site Scripting via "Name" field (Taxons, Products, Options, …

Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The code…

πŸ“… Published: May 10, 2024, 3:29 p.m. πŸ”„ Last Modified: July 12, 2025, 10:15 p.m.

9.7

CVSS3.1

CVE-2024-34070 - Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise

Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on t…

πŸ“… Published: May 10, 2024, 3:21 p.m. πŸ”„ Last Modified: July 12, 2025, 10:01 p.m.

5.5

CVSS3.1

CVE-2024-30801 -

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.

πŸ“… Published: May 10, 2024, 3:14 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:47 p.m.

5.3

CVSS4.0

CVE-2024-4720 - Campcodes Complete Web-Based School Management System approve_petty_cash.php cross site scripting

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The a…

πŸ“… Published: May 10, 2024, 3 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 8:23 p.m.

5.3

CVSS4.0

CVE-2024-4719 - Campcodes Complete Web-Based School Management System delete_record.php cross site scripting

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The atta…

πŸ“… Published: May 10, 2024, 3 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 7:03 p.m.

7.8

CVSS3.1

CVE-2024-4044 - Deserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudio

A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2…

πŸ“… Published: May 10, 2024, 2:59 p.m. πŸ”„ Last Modified: July 12, 2025, 3:42 p.m.

9

CVSS3.1

CVE-2024-32964 - lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server…

πŸ“… Published: May 10, 2024, 2:49 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 2:35 p.m.
Total resulsts: 343975
Page 9387 of 34,398
Β« previous page Β» next page
Filters