5.1
CVE-2024-13201 - wander-chu SpringBoot-Blog Admin Attachment AttachtController.java upload unrestricted upload
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. The manipulation of the argume…
6.9
CVE-2024-13200 - wander-chu SpringBoot-Blog HTTP POST Request BaseInterceptor.java preHandle access control
A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. The manipulation leads to improper access co…
5.3
CVE-2023-27531 -
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
3.6
CVE-2024-37372 - nodejs: Permission model improperly processes UNC paths
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.
5.3
CVE-2024-13199 - langhsu Mblog Blog System Search Bar search cross site scripting
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely.…
6.3
CVE-2024-13198 - langhsu Mblog Blog System login observable response discrepancy
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The e…
5.3
CVE-2024-13197 - donglight bookstore电商书城系统说明 AdminUserControlle.java updateUser cross site scripting
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads to cross site scripting. The attack may be in…
5.3
CVE-2024-13196 - donglight bookstore电商书城系统说明 BookInfoController.java BookSearchList cross site scripting
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore/web/controller/BookInfoController.java. The manipulation of the argument keywords leads to cross si…
5.4
CVE-2024-56377 -
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (whi…
9.6
CVE-2024-55224 -
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.