4.8

CVSS3.1

CVE-2024-34349 - Sylius potentially vulnerable to Cross Site Scripting via "Name" field (Taxons, Products, Options, …

Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The code…

πŸ“… Published: May 10, 2024, 3:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.7

CVSS3.1

CVE-2024-34070 - Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise

Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on t…

πŸ“… Published: May 10, 2024, 3:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-30801 -

SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.

πŸ“… Published: May 10, 2024, 3:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-4720 - Campcodes Complete Web-Based School Management System approve_petty_cash.php cross site scripting

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The a…

πŸ“… Published: May 10, 2024, 3 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 8:23 p.m.

5.3

CVSS4.0

CVE-2024-4719 - Campcodes Complete Web-Based School Management System delete_record.php cross site scripting

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The atta…

πŸ“… Published: May 10, 2024, 3 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 7:03 p.m.

7.8

CVSS3.1

CVE-2024-4044 - Deserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudio

A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2…

πŸ“… Published: May 10, 2024, 2:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2024-32964 - lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server…

πŸ“… Published: May 10, 2024, 2:49 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 2:35 p.m.

6.5

CVSS3.1

CVE-2024-33774 -

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."

πŸ“… Published: May 10, 2024, 2:45 p.m. πŸ”„ Last Modified: May 21, 2025, 2:42 p.m.

6.5

CVSS3.1

CVE-2024-33773 -

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."

πŸ“… Published: May 10, 2024, 2:44 p.m. πŸ”„ Last Modified: May 21, 2025, 2:42 p.m.

7.5

CVSS3.1

CVE-2024-31441 - Arbitrary File Reading in DataEase

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.

πŸ“… Published: May 10, 2024, 2:43 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 5:49 p.m.
Total resulsts: 349182
Page 9908 of 34,919
Β« previous page Β» next page
Filters