4.8

CVSS4.0

CVE-2024-12353 - SourceCodester Phone Contact Manager System User Menu MenuDisplayStart input validation

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name leads to improper input validation. Attacking lo…

πŸ“… Published: Dec. 9, 2024, 1 a.m. πŸ”„ Last Modified: Dec. 12, 2024, 1:45 p.m.

5.3

CVSS4.0

CVE-2024-12352 - TOTOLINK EX1800T cstecgi.cgi sub_40662C stack-based overflow

A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The …

πŸ“… Published: Dec. 9, 2024, 1 a.m. πŸ”„ Last Modified: Dec. 10, 2024, 11:31 p.m.

5.3

CVSS4.0

CVE-2024-12351 - JFinalCMS File Content ContentModel.java findPage sql injection

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the a…

πŸ“… Published: Dec. 9, 2024, 12:31 a.m. πŸ”„ Last Modified: Dec. 11, 2024, 5:32 p.m.

5.3

CVSS4.0

CVE-2024-12350 - JFinalCMS Template TemplateController.java update command injection

A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The manipulation of the argument content leads to command injection…

πŸ“… Published: Dec. 9, 2024, 12:31 a.m. πŸ”„ Last Modified: Dec. 11, 2024, 5:32 p.m.

6.9

CVSS4.0

CVE-2024-12349 - JFinalCMS save cross-site request forgery

A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the p…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: Dec. 11, 2024, 5:34 p.m.

5.3

CVSS4.0

CVE-2024-12348 - Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scrip…

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross si…

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: June 4, 2025, 7:13 p.m.

9.1

CVSS3.1

CVE-2024-53441 -

An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-48956 -

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-53450 -

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 10:34 p.m.

9.8

CVSS3.1

CVE-2022-38947 -

SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.

πŸ“… Published: Dec. 9, 2024, midnight πŸ”„ Last Modified: May 17, 2025, 1:57 a.m.
Total resulsts: 348147
Page 7481 of 34,815
Β« previous page Β» next page
Filters