6.5

CVSS3.1

CVE-2024-33901 -

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

๐Ÿ“… Published: May 20, 2024, 8:21 p.m. ๐Ÿ”„ Last Modified: June 13, 2025, 4:13 p.m.

7.9

CVSS3.1

CVE-2024-29000 - SolarWinds Platform Reflected XSS Vulnerability

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

๐Ÿ“… Published: May 20, 2024, 6:26 p.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 10:51 p.m.

8.3

CVSS3.1

CVE-2023-49335 -

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

๐Ÿ“… Published: May 20, 2024, 5:55 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:28 p.m.

8.3

CVSS3.1

CVE-2023-49334 -

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

๐Ÿ“… Published: May 20, 2024, 5:55 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:28 p.m.

8.3

CVSS3.1

CVE-2023-49333 -

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

๐Ÿ“… Published: May 20, 2024, 5:51 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:28 p.m.

8.2

CVSS3.1

CVE-2024-34949 -

SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.

๐Ÿ“… Published: May 20, 2024, 5:47 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 8:29 p.m.

8.3

CVSS3.1

CVE-2023-49332 -

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

๐Ÿ“… Published: May 20, 2024, 5:45 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:28 p.m.

8.3

CVSS3.1

CVE-2023-49331 -

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

๐Ÿ“… Published: May 20, 2024, 5:35 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 1:27 p.m.

7.5

CVSS3.1

CVE-2024-34193 -

smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.

๐Ÿ“… Published: May 20, 2024, 5:32 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2026, 3:37 a.m.

8

CVSS3.1

CVE-2024-35578 -

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

๐Ÿ“… Published: May 20, 2024, 5:30 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 2:29 p.m.
Total resulsts: 349182
Page 9762 of 34,919
ยซ previous page ยป next page
Filters