5.3

CVSS4.0

CVE-2024-51485 - Insufficient Validation in Plugins (Activation/Deactivation) in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change wโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:45 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 8:06 p.m.

5.5

CVSS3.1

CVE-2024-51486 - Stored Cross-Site Scripting in Ampache

Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URLโ€Š-โ€ŠFavicon". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript.โ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:44 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:45 a.m.

5.3

CVSS4.0

CVE-2024-51487 - Insufficient Validation in Catalog (Activation/Deactivation) in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating catalog. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change wโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:43 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 7:37 p.m.

5.3

CVSS4.0

CVE-2024-51488 - Insufficient Validation in Delete Message in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to delete messages to any useโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:42 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 8:12 p.m.

5.3

CVSS4.0

CVE-2024-51489 - Insufficient Message Token Validation in Ampache

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to send messagesโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:37 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 8:12 p.m.

5.5

CVSS3.1

CVE-2024-51490 - Stored Cross-Site Scripting in Ampache

Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This โ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:35 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 8:13 p.m.

5.3

CVSS4.0

CVE-2024-11078 - code-projects Job Recruitment register.php cross site scripting

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e/role leads to cross site scripting. The attack can be launched remotely. The exโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:31 p.m. ๐Ÿ”„ Last Modified: Sept. 30, 2025, 2:26 p.m.

9.1

CVSS3.1

CVE-2024-51747 - Arbitrary File Read and Delete in kanboard

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLiโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:22 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2024, 1:55 p.m.

9.1

CVSS3.1

CVE-2024-51748 - Remote code execution through language setting in kanboard

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `sโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:20 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2024, 2:44 p.m.

4.1

CVSS3.1

CVE-2024-51992 - Method Exposure Vulnerability in Modals in orchid/platform

Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue (CWE-749: Exposed Dangerous Method or Function) in the Orchid Platformโ€™s asynchronous modal functionality, affectiโ€ฆ

๐Ÿ“… Published: Nov. 11, 2024, 7:17 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2024, 2:45 p.m.
Total resulsts: 343974
Page 7422 of 34,398
ยซ previous page ยป next page
Filters