9.3

CVSS3.1

CVE-2024-57428 -

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, โ€ฆ

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:13 a.m.

5.3

CVSS3.1

CVE-2024-25883 -

The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-53586 -

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing daโ€ฆ

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-57429 -

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:13 a.m.

5.7

CVSS3.1

CVE-2025-22936 -

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2024-36557 -

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it โ€ฆ

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-54909 -

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-57426 -

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-57673 -

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 9:57 p.m.

4.8

CVSS3.1

CVE-2022-40490 -

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 7:40 p.m.
Total resulsts: 345209
Page 6436 of 34,521
ยซ previous page ยป next page
Filters