9.8

CVSS3.1

CVE-2024-34909 -

An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.

πŸ“… Published: May 15, 2024, 7:26 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:53 p.m.

6.3

CVSS3.1

CVE-2024-34906 -

An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.

πŸ“… Published: May 15, 2024, 7:26 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 3:53 p.m.

8.8

CVSS3.1

CVE-2024-33615 - CyberPower PowerPanel business Relative Path Traversal

A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.

πŸ“… Published: May 15, 2024, 7:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-33625 - CyberPower PowerPanel business Use of Hard-coded Password

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

πŸ“… Published: May 15, 2024, 7:19 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:18 p.m.

9.8

CVSS3.1

CVE-2024-34025 - CyberPower PowerPanel business Use of Hard-coded Password

CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.

πŸ“… Published: May 15, 2024, 7:17 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 2:12 p.m.

5.3

CVSS4.0

CVE-2024-4909 - Campcodes Complete Web-Based School Management System student_due_payment.php sql injection

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /view/student_due_payment.php. The manipulation of the argument due_year leads to sql injection. It is possible to launch the attac…

πŸ“… Published: May 15, 2024, 7 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 9:20 p.m.

5.3

CVSS4.0

CVE-2024-4908 - Campcodes Complete Web-Based School Management System student_attendance_history1.php sql injection

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated…

πŸ“… Published: May 15, 2024, 7 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 9:13 p.m.

5.3

CVSS4.0

CVE-2024-4907 - Campcodes Complete Web-Based School Management System show_student2.php sql injection

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/show_student2.php. The manipulation of the argument grade leads to sql injection. The attack can be initiated remotely. T…

πŸ“… Published: May 15, 2024, 6:31 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 9:11 p.m.

5.3

CVSS4.0

CVE-2024-4906 - Campcodes Complete Web-Based School Management System show_student1.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_student1.php. The manipulation of the argument grade leads to sql injection. It is possible to initiate the attack remotely.…

πŸ“… Published: May 15, 2024, 6:31 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 9:05 p.m.

8.8

CVSS3.1

CVE-2024-35102 -

Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.

πŸ“… Published: May 15, 2024, 6:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9846 of 34,919
Β« previous page Β» next page
Filters