5.4

CVSS3.1

CVE-2024-48706 -

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

5.2

CVSS3.1

CVE-2024-49210 -

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web applicat…

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 7:35 p.m.

7.5

CVSS3.1

CVE-2024-48570 -

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 6:59 p.m.

9

CVSS3.1

CVE-2024-26519 -

An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 5:35 p.m.

5.3

CVSS3.1

CVE-2024-45526 -

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to degrade gradually.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 7:35 p.m.

8.2

CVSS3.1

CVE-2024-46482 -

An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 6:35 p.m.

5.4

CVSS3.1

CVE-2024-48656 -

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 24, 2024, 2:37 p.m.

4.8

CVSS3.1

CVE-2024-48652 -

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 25, 2024, 4:51 p.m.

7.8

CVSS3.1

CVE-2024-48605 -

An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 30, 2024, 9:19 p.m.

9.8

CVSS3.1

CVE-2024-46483 -

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.

πŸ“… Published: Oct. 22, 2024, midnight πŸ”„ Last Modified: Oct. 23, 2024, 7:35 p.m.
Total resulsts: 343923
Page 7654 of 34,393
Β« previous page Β» next page
Filters