6.3

CVSS3.1

CVE-2024-48291 -

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: May 27, 2025, 8:34 p.m.

6.5

CVSS3.1

CVE-2024-48107 -

SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: April 18, 2025, 1:19 a.m.

8

CVSS3.1

CVE-2024-48074 -

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: May 17, 2025, 2:14 a.m.

9.8

CVSS3.1

CVE-2024-48465 -

The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 6:35 p.m.

4.8

CVSS3.1

CVE-2024-51506 -

Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 2:53 p.m.

6.1

CVSS3.1

CVE-2024-42930 -

PbootCMS 3.2.8 is vulnerable to URL Redirect.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 6:43 p.m.

8.8

CVSS3.1

CVE-2024-48594 -

File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 9:09 p.m.

9.8

CVSS3.1

CVE-2024-39205 -

An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 9:35 p.m.

7.8

CVSS3.1

CVE-2024-50067 - uprobe: avoid out-of-bounds memory access of fetching args

In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a percpu buffer, and then copy to ring buffer to avoid non-atomic context problem. Sometimes user-space strings, arrays can be very large…

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

7.5

CVSS3.1

CVE-2024-42011 -

The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

πŸ“… Published: Oct. 28, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 6:35 p.m.
Total resulsts: 343942
Page 7605 of 34,395
Β« previous page Β» next page
Filters