6.3

CVSS3.1

CVE-2024-54761 -

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Sept. 29, 2025, 5:43 p.m.

6.5

CVSS3.1

CVE-2024-56114 -

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: July 16, 2025, 10:49 a.m.

8.8

CVSS3.1

CVE-2024-51229 -

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Sept. 29, 2025, 5:42 p.m.

0.0

CVE-2024-57362 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation duplicate of CVE-2024-54840. Notes: All CVE users should reference CVE-2024-54840 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Feb. 3, 2025, 6:15 p.m.

6.8

CVSS3.1

CVE-2024-48806 -

Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 16, 2025, 7:15 p.m.

6.3

CVSS3.1

CVE-2024-54762 -

Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: May 14, 2025, 6:26 p.m.

9.8

CVSS3.1

CVE-2023-28354 -

An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRP…

📅 Published: Jan. 9, 2025, midnight 🔄 Last Modified: Jan. 10, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2024-13195 - donglight bookstore电商书城系统说明 HttpUtil.java getHtml server-side request forgery

A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate…

📅 Published: Jan. 8, 2025, 11:31 p.m. 🔄 Last Modified: Aug. 22, 2025, 9:41 p.m.

5.3

CVSS4.0

CVE-2024-13194 - Sucms admin_members.php sql injection

A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to…

📅 Published: Jan. 8, 2025, 11:31 p.m. 🔄 Last Modified: June 5, 2025, 7:45 p.m.

5.3

CVSS4.0

CVE-2024-13193 - SEMCMS Image Library Management Page SEMCMS_Images.php sql injection

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The e…

📅 Published: Jan. 8, 2025, 11 p.m. 🔄 Last Modified: April 4, 2025, 4:59 p.m.
Total resulsts: 343968
Page 6699 of 34,397
« previous page » next page
Filters