8.7

CVSS4.0

CVE-2024-52302 - common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper valida…

📅 Published: Nov. 14, 2024, 3:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2024-11136 - Arbitrary file removal via path traversal in TCL Camera

The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from user’s external storage.

📅 Published: Nov. 14, 2024, 3:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7124 - Reflected XSS in DInGO dLibra

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in…

📅 Published: Nov. 14, 2024, 3:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-11212 - SourceCodester Best Employee Management System fetch_product_details.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may…

📅 Published: Nov. 14, 2024, 3 p.m. 🔄 Last Modified: Nov. 19, 2024, 3:48 p.m.

5.1

CVSS4.0

CVE-2024-11211 - EyouCMS Website Logo unrestricted upload

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u…

📅 Published: Nov. 14, 2024, 3 p.m. 🔄 Last Modified: Jan. 6, 2025, 5:57 p.m.

5.3

CVSS4.0

CVE-2024-11210 - EyouCMS FilemanagerLogic.php editFile path traversal

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has bee…

📅 Published: Nov. 14, 2024, 2:31 p.m. 🔄 Last Modified: Nov. 19, 2024, 6:42 p.m.

8.8

CVSS3.1

CVE-2024-10962 - Migration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attac…

📅 Published: Nov. 14, 2024, 1:54 p.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

6.5

CVSS3.1

CVE-2024-11215 - Path traversal vulnerability in EasyPHP

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecut…

📅 Published: Nov. 14, 2024, 1:37 p.m. 🔄 Last Modified: Jan. 7, 2026, 9:08 p.m.

5.3

CVSS4.0

CVE-2024-11209 - Apereo CAS 2FA login improper authentication

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the pub…

📅 Published: Nov. 14, 2024, 1:31 p.m. 🔄 Last Modified: Nov. 19, 2024, 7:14 p.m.

6.3

CVSS4.0

CVE-2024-11208 - Apereo CAS login session expiration

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation…

📅 Published: Nov. 14, 2024, 1:31 p.m. 🔄 Last Modified: Nov. 19, 2024, 7:38 p.m.
Total resulsts: 348401
Page 7799 of 34,841
« previous page » next page
Filters