5.7

CVSS3.1

CVE-2024-54128 - Directus has an HTML Injection in Comment

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulner…

πŸ“… Published: Dec. 5, 2024, 4:55 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 2:47 p.m.

6.9

CVSS4.0

CVE-2024-12233 - code-projects Online Notice Board Profile Picture registration.php unrestricted upload

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may b…

πŸ“… Published: Dec. 5, 2024, 4:31 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2024-12232 - code-projects Simple CRUD Functionality index.php cross site scripting

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The ex…

πŸ“… Published: Dec. 5, 2024, 4 p.m. πŸ”„ Last Modified: Feb. 27, 2025, 8:54 p.m.

6.9

CVSS4.0

CVE-2024-12231 - CodeZips Project Management System index.php sql injection

A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: Dec. 5, 2024, 4 p.m. πŸ”„ Last Modified: Dec. 9, 2024, 6:59 p.m.

0.0

CVE-2024-51728 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024. Notes: none.

πŸ“… Published: Dec. 5, 2024, 3:39 p.m. πŸ”„ Last Modified: Jan. 13, 2025, 10:15 a.m.

5.9

CVSS3.1

CVE-2024-10716 -

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

πŸ“… Published: Dec. 5, 2024, 3:28 p.m. πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

7.5

CVSS3.1

CVE-2024-53856 - rPGP Panics on Malformed Untrusted Input

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

πŸ“… Published: Dec. 5, 2024, 3:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-53857 - rPGP Potential Resource Exhaustion when handling Untrusted Messages

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

πŸ“… Published: Dec. 5, 2024, 3:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-12247 - Improper propagation of permission scheme updates across cluster nodes

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

πŸ“… Published: Dec. 5, 2024, 3:20 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:21 p.m.

5.5

CVSS3.1

CVE-2024-54001 - Kanboard allows a persistent HTML injection site scripting in settings page date format

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflect…

πŸ“… Published: Dec. 5, 2024, 3:17 p.m. πŸ”„ Last Modified: Dec. 5, 2024, 4:41 p.m.
Total resulsts: 345161
Page 7210 of 34,517
Β« previous page Β» next page
Filters