8.8

CVSS3.1

CVE-2024-34221 -

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

πŸ“… Published: May 13, 2024, 5:33 p.m. πŸ”„ Last Modified: April 18, 2025, 4:23 p.m.

5.9

CVSS3.1

CVE-2024-34222 -

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

πŸ“… Published: May 13, 2024, 5:30 p.m. πŸ”„ Last Modified: April 18, 2025, 4:23 p.m.

4.3

CVSS3.1

CVE-2024-34223 -

Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

πŸ“… Published: May 13, 2024, 5:29 p.m. πŸ”„ Last Modified: April 18, 2025, 4:23 p.m.

0.0

CVE-2024-4842 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Not a vulnerability

πŸ“… Published: May 13, 2024, 4:52 p.m. πŸ”„ Last Modified: May 30, 2024, 8:15 p.m.

6.5

CVSS3.1

CVE-2023-50718 - NocoDB SQL Injection vulnerability

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202…

πŸ“… Published: May 13, 2024, 4:08 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:52 p.m.

5.7

CVSS3.1

CVE-2023-50717 - NocoDB Allows Preview of File with Dangerous Content

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. T…

πŸ“… Published: May 13, 2024, 4:05 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:52 p.m.

9.8

CVSS3.1

CVE-2024-34706 - @valtimo/components exposes access token to form.io

Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is exposed to `api.form.io` via the the `x-jwt-token` header. An attacker can retrieve personal information from this token, or use it to execute requests to t…

πŸ“… Published: May 13, 2024, 4:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-34701 - CreateWiki vulnerable to impersonation of wiki requester

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki request was made. Th…

πŸ“… Published: May 13, 2024, 3:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-34698 - Prototype Pollution in getQueryParam Function (URL Query Parser)

FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Function recursively merges an object containing user…

πŸ“… Published: May 13, 2024, 3:50 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 3:11 p.m.

7.2

CVSS3.1

CVE-2024-33250 -

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

πŸ“… Published: May 13, 2024, 3:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9891 of 34,919
Β« previous page Β» next page
Filters