6.1

CVSS3.1

CVE-2024-12715 - Asgard Security Scanner <= 0.7 - Reflected XSS

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Jan. 9, 2025, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:34 a.m.

6.1

CVSS3.1

CVE-2024-12714 - Backlink Monitoring Manager <= 0.1.3 - Reflected XSS

The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Jan. 9, 2025, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:33 a.m.

4.2

CVSS3.1

CVE-2024-10815 - PostLists <= 2.0.2 - Reflected XSS

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

πŸ“… Published: Jan. 9, 2025, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 3:32 p.m.

5.3

CVSS4.0

CVE-2025-0333 - leiyuxi cy-fast listData sql injection

A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the p…

πŸ“… Published: Jan. 9, 2025, 5 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:41 p.m.

6.9

CVSS4.0

CVE-2025-0331 - YunzMall HTTP POST Request ResetpwdController.php changePwd password recovery

A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to weak password r…

πŸ“… Published: Jan. 9, 2025, 4:31 a.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-0328 - KaiYuanTong ECT Platform HTTP POST Request runCode.php command injection

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipulation of the argument code leads to command i…

πŸ“… Published: Jan. 9, 2025, 4:31 a.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2024-13213 - SingMR HouseRent toAdminUpdateHousePage cross site scripting

A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: Jan. 9, 2025, 4 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 6:48 p.m.

5.3

CVSS4.0

CVE-2024-13212 - SingMR HouseRent AddHouseController.java upload unrestricted upload

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the…

πŸ“… Published: Jan. 9, 2025, 4 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 5:40 p.m.

5.3

CVSS4.0

CVE-2024-13211 - SingMR HouseRent AdminController.java access control

A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. Th…

πŸ“… Published: Jan. 9, 2025, 3:31 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 5:41 p.m.

5.1

CVSS4.0

CVE-2024-13210 - donglight bookstoreη”΅ε•†δΉ¦εŸŽη³»η»Ÿθ―΄ζ˜Ž AdminBookController. java uploadPicture unrestricted upload

A vulnerability was found in donglight bookstoreη”΅ε•†δΉ¦εŸŽη³»η»Ÿθ―΄ζ˜Ž 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads…

πŸ“… Published: Jan. 9, 2025, 3:31 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 9:39 p.m.
Total resulsts: 343944
Page 6693 of 34,395
Β« previous page Β» next page
Filters