5.3

CVSS4.0

CVE-2024-5105 - Campcodes Complete Web-Based School Management System student_payment_details.php sql injection

A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_payment_details.php. The manipulation of the argument index leads to sql injection. It is possible to initiate the attack remote…

πŸ“… Published: May 19, 2024, 10:31 p.m. πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.

4.9

CVSS3.0

CVE-2024-4284 - Denial of Service in mintplex-labs/anything-llm

A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. By exploiti…

πŸ“… Published: May 19, 2024, 10:23 p.m. πŸ”„ Last Modified: July 10, 2025, 4:14 p.m.

5.3

CVSS4.0

CVE-2024-5104 - Campcodes Complete Web-Based School Management System student_grade_wise.php sql injection

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/student_grade_wise.php. The manipulation of the argument grade leads to sql injection. The attack may be laun…

πŸ“… Published: May 19, 2024, 10 p.m. πŸ”„ Last Modified: July 12, 2025, 10:31 p.m.

5.3

CVSS4.0

CVE-2024-5103 - Campcodes Complete Web-Based School Management System student_first_payment.php sql injection

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/student_first_payment.php. The manipulation of the argument grade leads to sql injection. The attack…

πŸ“… Published: May 19, 2024, 8:31 p.m. πŸ”„ Last Modified: July 12, 2025, 10:09 p.m.

9.8

CVSS3.1

CVE-2024-36080 -

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

πŸ“… Published: May 19, 2024, 8:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-36081 -

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

πŸ“… Published: May 19, 2024, 8:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-36078 -

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

πŸ“… Published: May 19, 2024, 7:36 p.m. πŸ”„ Last Modified: April 15, 2025, 4:38 p.m.

8.8

CVSS3.1

CVE-2024-36076 -

Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.

πŸ“… Published: May 19, 2024, 7:22 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 9:22 p.m.

7.5

CVSS3.1

CVE-2024-36070 -

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)

πŸ“… Published: May 19, 2024, 6:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2024-36053 -

In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.

πŸ“… Published: May 19, 2024, 3:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9774 of 34,919
Β« previous page Β» next page
Filters