5.3

CVSS4.0

CVE-2024-4975 - code-projects Simple Chat System Message cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component Message Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: May 16, 2024, 10 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:42 p.m.

8.8

CVSS3.1

CVE-2024-4352 - Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the โ€˜yearโ€™ parameter of that function due to insuffiโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

7.3

CVSS3.1

CVE-2024-4222 - Tutor LMS Pro <= 2.7.0 - Missing Authorization

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or deleteโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

8.8

CVSS3.1

CVE-2024-4351 - Tutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-lโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

5.3

CVSS4.0

CVE-2024-4974 - code-projects Simple Chat System register.php cross site scripting

A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has beenโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:41 p.m.

5.3

CVSS4.0

CVE-2024-4973 - code-projects Simple Chat System register.php sql injection

A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument name/number/address leads to sql injection. The attack can be initiated remotely. The exploit has been discloโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:31 a.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 6:41 p.m.

9.6

CVSS3.0

CVE-2024-2361 - Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webui

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize โ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:03 a.m. ๐Ÿ”„ Last Modified: July 9, 2025, 2:38 p.m.

9

CVSS3.0

CVE-2024-2366 - Remote Code Execution in parisneo/lollms-webui

A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path sanitization, allowiโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:03 a.m. ๐Ÿ”„ Last Modified: July 9, 2025, 2:37 p.m.

9.8

CVSS3.0

CVE-2024-4078 - Arbitrary Code Execution in parisneo/lollms

A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, โ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.0

CVE-2024-3435 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an aโ€ฆ

๐Ÿ“… Published: May 16, 2024, 9:03 a.m. ๐Ÿ”„ Last Modified: July 9, 2025, 2:33 p.m.
Total resulsts: 349182
Page 9835 of 34,919
ยซ previous page ยป next page
Filters