7.2

CVSS3.1

CVE-2024-46481 -

The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 1:35 p.m.

6.5

CVSS3.1

CVE-2024-57487 -

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 6:48 p.m.

5.4

CVSS3.1

CVE-2023-42234 -

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 5:44 p.m.

5.3

CVSS3.1

CVE-2024-46919 -

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 4:06 p.m.

6.5

CVSS3.1

CVE-2024-57488 -

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 6:44 p.m.

7.5

CVSS3.1

CVE-2023-42232 -

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 5:44 p.m.

5.4

CVSS3.1

CVE-2023-42243 -

In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

9.1

CVSS3.1

CVE-2024-57811 -

In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.8

CVSS3.1

CVE-2023-42242 -

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

7.5

CVSS3.1

CVE-2023-42225 -

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 5:43 p.m.
Total resulsts: 347742
Page 7028 of 34,775
ยซ previous page ยป next page
Filters