6.9

CVSS4.0

CVE-2024-4927 - SourceCodester Simple Online Bidding System unrestricted upload

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. Theโ€ฆ

๐Ÿ“… Published: May 16, 2024, 2:31 a.m. ๐Ÿ”„ Last Modified: Dec. 9, 2024, 10:41 p.m.

6.4

CVSS3.1

CVE-2024-4984 - Yoast SEO <= 22.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜display_nameโ€™ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level accessโ€ฆ

๐Ÿ“… Published: May 16, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-4926 - SourceCodester School Intramurals Student Attendance Management System manage_student.php sql injecโ€ฆ

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to laโ€ฆ

๐Ÿ“… Published: May 16, 2024, 2 a.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:30 p.m.

5.3

CVSS4.0

CVE-2024-4925 - SourceCodester School Intramurals Student Attendance Management System manage_course.php sql injectโ€ฆ

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be iโ€ฆ

๐Ÿ“… Published: May 16, 2024, 1:31 a.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:29 p.m.

5.3

CVSS4.0

CVE-2024-4923 - Codezips E-Commerce Site addproduct.php unrestricted upload

A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: May 16, 2024, 1:31 a.m. ๐Ÿ”„ Last Modified: July 13, 2025, 11:31 a.m.

5.3

CVSS4.0

CVE-2024-4922 - SourceCodester Simple Image Stack Website cross site scripting

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the โ€ฆ

๐Ÿ“… Published: May 16, 2024, 1 a.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:25 p.m.

5.3

CVSS4.0

CVE-2024-4921 - SourceCodester Employee and Visitor Gate Pass Logging System unrestricted upload

A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to lโ€ฆ

๐Ÿ“… Published: May 16, 2024, 12:31 a.m. ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:23 p.m.

6.9

CVSS4.0

CVE-2024-4920 - SourceCodester Online Discussion Forum Site registerH.php unrestricted upload

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit hasโ€ฆ

๐Ÿ“… Published: May 16, 2024, midnight ๐Ÿ”„ Last Modified: Feb. 10, 2025, 1:20 p.m.

5.3

CVSS3.1

CVE-2024-4603 - Excessive time spent checking DSA keys and parameters

Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are beingโ€ฆ

๐Ÿ“… Published: May 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-33870 - ghostscript: path traversal to arbitrary files if the current directory is in the permitted paths

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ iโ€ฆ

๐Ÿ“… Published: May 16, 2024, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 7:14 p.m.
Total resulsts: 349182
Page 9842 of 34,919
ยซ previous page ยป next page
Filters