6.1

CVSS3.1

CVE-2024-57033 -

WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:30 p.m.

9.8

CVSS3.1

CVE-2024-57031 -

WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-45341 - Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-45336 - Sensitive headers incorrectly sent after cross-domain redirect in net/http

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, th…

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-57032 -

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 3:15 p.m.

8.1

CVSS3.1

CVE-2024-57030 -

Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:24 p.m.

9.8

CVSS3.1

CVE-2024-57035 -

WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-57370 -

Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-57372 -

Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters

πŸ“… Published: Jan. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-56144 - Stored XSS-LibreNMS-Display Name 2 in librenms

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versions up to 24.11.0 allow remote attackers to injec…

πŸ“… Published: Jan. 16, 2025, 10:28 p.m. πŸ”„ Last Modified: April 28, 2025, 4:44 p.m.
Total resulsts: 346643
Page 6810 of 34,665
Β« previous page Β» next page
Filters