5.3

CVSS4.0

CVE-2024-13212 - SingMR HouseRent AddHouseController.java upload unrestricted upload

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the…

📅 Published: Jan. 9, 2025, 4 a.m. 🔄 Last Modified: Oct. 15, 2025, 5:40 p.m.

5.3

CVSS4.0

CVE-2024-13211 - SingMR HouseRent AdminController.java access control

A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. Th…

📅 Published: Jan. 9, 2025, 3:31 a.m. 🔄 Last Modified: Oct. 15, 2025, 5:41 p.m.

5.1

CVSS4.0

CVE-2024-13210 - donglight bookstore电商书城系统说明 AdminBookController. java uploadPicture unrestricted upload

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads…

📅 Published: Jan. 9, 2025, 3:31 a.m. 🔄 Last Modified: Aug. 22, 2025, 9:39 p.m.

5.1

CVSS4.0

CVE-2024-13209 - Redaxo CMS Structure Management Page index.php cross site scripting

A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument A…

📅 Published: Jan. 9, 2025, 3 a.m. 🔄 Last Modified: June 24, 2025, 2:30 p.m.

8.5

CVSS4.0

CVE-2024-13206 - REVE Antivirus reveinstall default permission

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit ha…

📅 Published: Jan. 9, 2025, 3 a.m. 🔄 Last Modified: Jan. 9, 2025, 3:58 p.m.

5.1

CVSS4.0

CVE-2024-13205 - kurniaramadhan E-Commerce-PHP Create Product Page create_product.php cross site scripting

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/create_product.php of the component Create Product Page. The manipulation of the argument Name leads to cross site scripting. The…

📅 Published: Jan. 9, 2025, 2:31 a.m. 🔄 Last Modified: July 2, 2025, 7:10 p.m.

5.3

CVSS4.0

CVE-2024-13204 - kurniaramadhan E-Commerce-PHP blog-details.php sql injection

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /blog-details.php. The manipulation of the argument blog_id leads to sql injection. The attack can be launched remotely. The explo…

📅 Published: Jan. 9, 2025, 2 a.m. 🔄 Last Modified: July 2, 2025, 7:10 p.m.

6.9

CVSS4.0

CVE-2024-13203 - kurniaramadhan E-Commerce-PHP cross-site request forgery

A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did no…

📅 Published: Jan. 9, 2025, 2 a.m. 🔄 Last Modified: July 2, 2025, 7:10 p.m.

5.1

CVSS4.0

CVE-2024-13202 - wander-chu SpringBoot-Blog Blog Article PageController.java modifiyArticle cross site scripting

A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Handler. The manipulation of the argument conten…

📅 Published: Jan. 9, 2025, 1:31 a.m. 🔄 Last Modified: Aug. 22, 2025, 4:46 p.m.

5.1

CVSS4.0

CVE-2024-13201 - wander-chu SpringBoot-Blog Admin Attachment AttachtController.java upload unrestricted upload

A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. The manipulation of the argume…

📅 Published: Jan. 9, 2025, 1:31 a.m. 🔄 Last Modified: Aug. 22, 2025, 4:47 p.m.
Total resulsts: 343947
Page 6694 of 34,395
« previous page » next page
Filters