5.3

CVSS4.0

CVE-2024-12486 - code-projects Online Class and Exam Scheduling System rank_update.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. Th…

πŸ“… Published: Dec. 11, 2024, 8:31 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 5:35 p.m.

5.3

CVSS4.0

CVE-2024-12485 - code-projects Online Class and Exam Scheduling System department.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remot…

πŸ“… Published: Dec. 11, 2024, 8:31 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 5:34 p.m.

6.9

CVSS4.0

CVE-2024-12484 - Codezips Technical Discussion Forum signuppost.php sql injection

A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…

πŸ“… Published: Dec. 11, 2024, 8 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 5:34 p.m.

6.3

CVSS4.0

CVE-2024-12483 - Dromara UJCMS User ID id authorization

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is …

πŸ“… Published: Dec. 11, 2024, 8 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:12 p.m.

5.3

CVSS4.0

CVE-2024-12482 - cjbi wetech-cms Database Backup BackupFileUtil.java backup path traversal

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basic-common\src\main\java\tech\wetech\basic\util\BackupFileUtil.java of the component Database Backup Handler. The manipula…

πŸ“… Published: Dec. 11, 2024, 7:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:11 p.m.

5.3

CVSS4.0

CVE-2024-12481 - cjbi wetech-cms UserDao.java findUser sql injection

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\UserDao.java. The manipulation of the argument searchValue/gId/rId leads to…

πŸ“… Published: Dec. 11, 2024, 7:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:11 p.m.

5.1

CVSS4.0

CVE-2024-47834 - GHSL-2024-280: Gstreamer Use-After-Free read in Matroska CodecPrivate

GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_parse_stream function, …

πŸ“… Published: Dec. 11, 2024, 7:18 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

6.8

CVSS4.0

CVE-2024-47835 - GHSL-2024-263: Gstreamer NULL-pointer dereference in LRC subtitle parser

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer returned by this ca…

πŸ“… Published: Dec. 11, 2024, 7:17 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

5.1

CVSS4.0

CVE-2024-47778 - GHSL-2024-258: GStreamer has an OOB-read in gst_wavparse_adtl_chunk

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds of the data buffer.…

πŸ“… Published: Dec. 11, 2024, 7:16 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

5.1

CVSS4.0

CVE-2024-47777 - GHSL-2024-259: GStreamer has an OOB-read in gst_wavparse_smpl_chunk

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size of the data buffer i…

πŸ“… Published: Dec. 11, 2024, 7:16 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.
Total resulsts: 346713
Page 7272 of 34,672
Β« previous page Β» next page
Filters