4.4

CVSS3.0

CVE-2024-3924 - Code Injection in huggingface/text-generation-inference

A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installi…

πŸ“… Published: May 30, 2024, 2:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-4330 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious HTTP request, an attacker can traverse the d…

πŸ“… Published: May 30, 2024, 2:43 p.m. πŸ”„ Last Modified: July 9, 2025, 2:27 p.m.

6.9

CVSS4.0

CVE-2024-5517 - itsourcecode Online Blood Bank Management System changepwd.php sql injection

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file changepwd.php. The manipulation of the argument useremail leads to sql injection. The attack may be launched remotely. T…

πŸ“… Published: May 30, 2024, 2:31 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 3:11 p.m.

5.3

CVSS4.0

CVE-2024-5516 - itsourcecode Online Blood Bank Management System massage.php sql injection

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file massage.php. The manipulation of the argument bid leads to sql injection. The attack can be launched remotely. …

πŸ“… Published: May 30, 2024, 1:31 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 3:12 p.m.

5.3

CVSS4.0

CVE-2024-5515 - SourceCodester Stock Management System createBrand.php sql injection

A vulnerability was found in SourceCodester Stock Management System 1.0. It has been classified as critical. Affected is an unknown function of the file createBrand.php. The manipulation of the argument brandName leads to sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: May 30, 2024, 1 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 1:56 p.m.

7.5

CVSS3.1

CVE-2024-3584 - Path Traversal in qdrant/qdrant

qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoint. By manipulating the `name` parameter through URL encoding, an attacker can upload a file to an arbitrary location on the system, such as `/root/po…

πŸ“… Published: May 30, 2024, 12:33 p.m. πŸ”„ Last Modified: July 10, 2025, 6:21 p.m.

10

CVSS4.0

CVE-2024-1100 - SQLi in Vadi Corporate Information Systems' DIGIKENT GIS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection.This issue affects DIGIKENT GIS: through 2.23.5.

πŸ“… Published: May 30, 2024, 11:49 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2022-43841 - IBM Aspera Console information disclosure

IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.

πŸ“… Published: May 30, 2024, 11:45 a.m. πŸ”„ Last Modified: Jan. 8, 2025, 5:13 p.m.

5.4

CVSS3.1

CVE-2022-43575 - IBM Aspera Console cross-site scripting

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 23864…

πŸ“… Published: May 30, 2024, 11:38 a.m. πŸ”„ Last Modified: Jan. 8, 2025, 5:22 p.m.

4.6

CVSS3.1

CVE-2022-43384 - IBM Aspera Console cross-site scripting

IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 23864…

πŸ“… Published: May 30, 2024, 11:36 a.m. πŸ”„ Last Modified: Jan. 8, 2025, 5:25 p.m.
Total resulsts: 349182
Page 9627 of 34,919
Β« previous page Β» next page
Filters