8.8

CVSS3.1

CVE-2024-55411 -

An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-53522 -

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46603 -

An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:14 p.m.

7.5

CVSS3.1

CVE-2024-46601 -

Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:13 p.m.

8.8

CVSS3.1

CVE-2024-55555 -

Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2022-41573 -

An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50660 -

File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:47 p.m.

7.8

CVSS3.1

CVE-2024-55412 -

A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disc…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-48245 -

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which a…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 4:06 p.m.

8.1

CVSS3.1

CVE-2022-45186 -

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:33 p.m.
Total resulsts: 346573
Page 7008 of 34,658
Β« previous page Β» next page
Filters