8.8

CVSS3.1

CVE-2024-31445 - SQL Injection vulnerability in automation_get_new_graphs_sql

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalatiโ€ฆ

๐Ÿ“… Published: May 13, 2024, 3:05 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 6:13 p.m.

4.6

CVSS3.1

CVE-2024-31444 - Cacti XSS vulnerability in lib/html.php by reading dirty data stored in database

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` functiโ€ฆ

๐Ÿ“… Published: May 13, 2024, 3:03 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

5.7

CVSS3.1

CVE-2024-31443 - Cacti XSS vulnerability in lib/html_tree.php by reading dirty data stored in database

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finallโ€ฆ

๐Ÿ“… Published: May 13, 2024, 3:01 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-30268 - Cacti XSS vulnerability in display_settings

Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e977โ€ฆ

๐Ÿ“… Published: May 13, 2024, 2:56 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-30259 - FastDDS heap buffer overflow when publisher sends malformed packet

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fastโ€ฆ

๐Ÿ“… Published: May 13, 2024, 2:45 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2025, 6:16 p.m.

8.2

CVSS3.1

CVE-2024-30258 - FastDDS crash when publisher send malformed packet

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fโ€ฆ

๐Ÿ“… Published: May 13, 2024, 2:41 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2025, 6:19 p.m.

10

CVSS3.1

CVE-2024-29895 - Cacti command injection in cmd_realtime.php

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$pollerโ€ฆ

๐Ÿ“… Published: May 13, 2024, 2:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-29894 - Cacti Cross-site Scripting vulnerability when using JavaScript based messaging API

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-502โ€ฆ

๐Ÿ“… Published: May 13, 2024, 2:24 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 5:47 p.m.

5.3

CVSS4.0

CVE-2024-4820 - SourceCodester Online Computer and Laptop Store unrestricted upload

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be โ€ฆ

๐Ÿ“… Published: May 13, 2024, 2 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 3:28 p.m.

3.1

CVSS3.1

CVE-2024-28866 - GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up

GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate validation. Attackerโ€ฆ

๐Ÿ“… Published: May 13, 2024, 1:53 p.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 2:43 p.m.
Total resulsts: 349182
Page 9893 of 34,919
ยซ previous page ยป next page
Filters