9.8

CVSS3.1

CVE-2024-33164 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 5:17 p.m.

9.8

CVSS3.1

CVE-2024-33153 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 5:17 p.m.

8.8

CVSS3.1

CVE-2024-33144 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 3:39 p.m.

9.8

CVSS3.1

CVE-2024-33124 -

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:55 p.m.

6.3

CVSS3.1

CVE-2024-33122 -

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:55 p.m.

9.8

CVSS3.1

CVE-2024-33120 -

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: May 1, 2025, 2:55 p.m.

8.8

CVSS3.1

CVE-2024-29150 -

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is able to create symlinks to sensitive and protected data in locations that are …

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-29149 -

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmwar…

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-33161 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 5:17 p.m.

7.3

CVSS3.1

CVE-2024-33148 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 5:16 p.m.
Total resulsts: 349182
Page 9963 of 34,919
Β« previous page Β» next page
Filters