3.7

CVSS3.1

CVE-2024-42188 - HCL Connections is vulnerable to a broken access control vulnerability

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

๐Ÿ“… Published: Nov. 14, 2024, 3:31 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 6:45 p.m.

5.4

CVSS3.1

CVE-2024-52505 - matrix-appservice-irc allows IRC Command injection in provisioning API

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matriโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3:29 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-52302 - common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validaโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2024-11136 - Arbitrary file removal via path traversal in TCL Camera

The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from userโ€™s external storage.

๐Ÿ“… Published: Nov. 14, 2024, 3:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-7124 - Reflected XSS in DInGO dLibra

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra softwareย in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run inโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-11212 - SourceCodester Best Employee Management System fetch_product_details.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack mayโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 3:48 p.m.

5.1

CVSS4.0

CVE-2024-11211 - EyouCMS Website Logo unrestricted upload

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be uโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 3 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2025, 5:57 p.m.

5.3

CVSS4.0

CVE-2024-11210 - EyouCMS FilemanagerLogic.php editFile path traversal

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 2:31 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 6:42 p.m.

8.8

CVSS3.1

CVE-2024-10962 - Migration, Backup, Staging โ€“ WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection

The Migration, Backup, Staging โ€“ WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attacโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 1:54 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 p.m.

6.5

CVSS3.1

CVE-2024-11215 - Path traversal vulnerability in EasyPHP

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutโ€ฆ

๐Ÿ“… Published: Nov. 14, 2024, 1:37 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 9:08 p.m.
Total resulsts: 348413
Page 7800 of 34,842
ยซ previous page ยป next page
Filters