5.3

CVSS3.1

CVE-2024-48533 -

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:45 p.m.

6.1

CVSS3.1

CVE-2024-45510 -

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the…

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 7:13 p.m.

7.2

CVSS3.1

CVE-2024-52769 -

An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 2:14 p.m.

9.8

CVSS3.1

CVE-2024-52770 -

An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: June 13, 2025, 2:17 p.m.

7.5

CVSS3.1

CVE-2024-48536 -

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:25 p.m.

6.1

CVSS3.1

CVE-2024-48534 -

A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:44 p.m.

9.8

CVSS3.1

CVE-2024-52677 -

HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 4:15 p.m.

0.0

CVE-2024-49203 -

Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product is not intended to defend against a developer who uses untrusted input directly in query construction.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-48531 -

A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:49 p.m.

7.5

CVSS3.1

CVE-2024-48530 -

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

πŸ“… Published: Nov. 20, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:52 p.m.
Total resulsts: 346555
Page 7520 of 34,656
Β« previous page Β» next page
Filters