6.9
CVE-2024-4927 - SourceCodester Simple Online Bidding System unrestricted upload
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. Theโฆ
6.4
CVE-2024-4984 - Yoast SEO <= 22.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โdisplay_nameโ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level accessโฆ
5.3
CVE-2024-4926 - SourceCodester School Intramurals Student Attendance Management System manage_student.php sql injecโฆ
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to laโฆ
5.3
CVE-2024-4925 - SourceCodester School Intramurals Student Attendance Management System manage_course.php sql injectโฆ
A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be iโฆ
5.3
CVE-2024-4923 - Codezips E-Commerce Site addproduct.php unrestricted upload
A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been dโฆ
5.3
CVE-2024-4922 - SourceCodester Simple Image Stack Website cross site scripting
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the โฆ
5.3
CVE-2024-4921 - SourceCodester Employee and Visitor Gate Pass Logging System unrestricted upload
A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to lโฆ
6.9
CVE-2024-4920 - SourceCodester Online Discussion Forum Site registerH.php unrestricted upload
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit hasโฆ
5.3
CVE-2024-4603 - Excessive time spent checking DSA keys and parameters
Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are beingโฆ
6.3
CVE-2024-33870 - ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ iโฆ