5.5

CVSS3.1

CVE-2023-49676 - CODESYS: Use after free vulnerability through corrupted project files

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

📅 Published: May 6, 2024, 11:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2023-49675 - CODESYS: Out-of-bounds write through corrupted project files

An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.

📅 Published: May 6, 2024, 11:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2023-6854 - Breakdance <= 1.7.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom postmeta

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated…

📅 Published: May 6, 2024, 11:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-23193 -

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation req…

📅 Published: May 6, 2024, 6:36 a.m. 🔄 Last Modified: April 10, 2025, 6:43 p.m.

6.5

CVSS3.1

CVE-2024-23188 -

Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information from the users accoun…

📅 Published: May 6, 2024, 6:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-23187 -

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user interaction. Please deplo…

📅 Published: May 6, 2024, 6:36 a.m. 🔄 Last Modified: Feb. 13, 2025, 5:33 p.m.

6.5

CVSS3.1

CVE-2024-23186 -

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer m…

📅 Published: May 6, 2024, 6:36 a.m. 🔄 Last Modified: Feb. 13, 2025, 5:33 p.m.

2.4

CVSS3.1

CVE-2024-4528 - SourceCodester Prison Management System user-record.php cross site scripting

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /Admin/user-record.php. The manipulation of the argument txtfullname leads to cross site scripting. The attack can be…

📅 Published: May 6, 2024, 6:31 a.m. 🔄 Last Modified: Feb. 10, 2025, 4:09 p.m.

3.5

CVSS3.1

CVE-2024-4527 - Campcodes Complete Web-Based School Management System student_payment_details2.php cross site scrip…

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/student_payment_details2.php. The manipulation of the argument index leads to cross site scripting. It is possible to laun…

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:04 p.m.

3.5

CVSS3.1

CVE-2024-4526 - Campcodes Complete Web-Based School Management System student_payment_details3.php cross site scrip…

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/student_payment_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be in…

📅 Published: May 6, 2024, 6 a.m. 🔄 Last Modified: Feb. 19, 2025, 6:05 p.m.
Total resulsts: 349182
Page 9973 of 34,919
« previous page » next page
Filters