2.3

CVSS4.0

CVE-2024-10749 - ThinkAdmin Plugs.php script deserialization

A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity o…

πŸ“… Published: Nov. 4, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 3:04 p.m.

2

CVSS4.0

CVE-2024-10748 - Cosmote Greece What's Up App Realm Database RealmDB.java default key

A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/desquared/kmmsharedmodule/db/RealmDB.java of the component Realm Database Handler. The manipulation of the argument defau…

πŸ“… Published: Nov. 4, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 6, 2024, 3:06 p.m.

5.3

CVSS4.0

CVE-2024-10747 - PHPGurukul Online Shopping Portal dom_data_th.php cross site scripting

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_th.php. The manipulation of the argument scripts leads to cross site scripting. Th…

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 5, 2024, 8:12 p.m.

6.8

CVSS3.1

CVE-2024-34883 -

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2024, 7:28 p.m.

6.1

CVSS3.1

CVE-2024-48059 -

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's b…

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: July 11, 2025, 1:58 p.m.

8

CVSS3.1

CVE-2024-51249 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 11, 2025, 3:06 p.m.

8

CVSS3.1

CVE-2024-45888 -

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:52 p.m.

6.5

CVSS3.1

CVE-2024-48463 -

Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Sept. 23, 2025, 1:51 a.m.

8

CVSS3.1

CVE-2024-51251 -

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 3:53 p.m.

6.8

CVSS3.1

CVE-2024-34885 -

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

πŸ“… Published: Nov. 4, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:35 p.m.
Total resulsts: 342279
Page 7352 of 34,228
Β« previous page Β» next page
Filters