6.4

CVSS3.1

CVE-2024-10881 - LUNA RADIO PLAYER <= 6.24.11.07 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

πŸ“… Published: Dec. 5, 2024, 3:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.6

CVSS3.0

CVE-2024-54014 -

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.

πŸ“… Published: Dec. 5, 2024, 2:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-12188 - 1000 Projects Library Management System stu.php sql injection

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /brains/stu.php. The manipulation of the argument useri leads to sql injection. The attack can be launched remotely. The…

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: Dec. 10, 2024, 11:18 p.m.

6.9

CVSS4.0

CVE-2024-12187 - 1000 Projects Library Management System showbook.php sql injection

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /showbook.php. The manipulation of the argument q leads to sql injection. It is possible to launch the attack remotely. The exploit has been disc…

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: Dec. 10, 2024, 3:25 p.m.

7.5

CVSS3.1

CVE-2024-53490 -

Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-53523 -

JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-37861 -

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-53470 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 9, 2025, 6:30 p.m.

5.4

CVSS3.1

CVE-2024-53457 -

A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 7, 2025, 2:55 p.m.

8.4

CVSS3.1

CVE-2024-53589 - binutils: objdump: buffer Overflow in the BFD library's handling of tekhex format files

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

πŸ“… Published: Dec. 5, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347742
Page 7475 of 34,775
Β« previous page Β» next page
Filters