9.4

CVSS3.1

CVE-2024-25511 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 7:03 p.m.

9.4

CVSS3.1

CVE-2024-25509 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file_download.aspx.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 7:05 p.m.

7.5

CVSS3.1

CVE-2024-34523 -

AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-33434 -

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filte…

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-25508 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 7:05 p.m.

7.5

CVSS3.1

CVE-2024-33781 -

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: June 16, 2025, 9:45 p.m.

9.6

CVSS3.1

CVE-2024-33857 -

An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 12:39 p.m.

9.8

CVSS3.1

CVE-2024-33155 -

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 5:17 p.m.

5.2

CVSS3.1

CVE-2024-34397 - glib2: Signal subscription vulnerabilities

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based c…

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.1

CVSS3.1

CVE-2024-33859 -

An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

πŸ“… Published: May 7, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 12:35 p.m.
Total resulsts: 349182
Page 9965 of 34,919
Β« previous page Β» next page
Filters