Show filters
1,908 Total Results
Displaying 431-440 of 1,908
Sort by:
Attacker Value
Unknown
CVE-2024-11130
Disclosure Date: November 12, 2024 (last updated February 27, 2025)
A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/msg.php. The manipulation of the argument keyword leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-11102
Disclosure Date: November 12, 2024 (last updated February 27, 2025)
A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /vm/doctor/edit-doc.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
0
Attacker Value
Unknown
CVE-2024-50636
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote Command Execution (RCE). This vulnerability arises because PyMOL treats .PYM files as Python scripts without properly validating or restricting the commands within the script, enabling attackers to run unauthorized commands in the context of the user running the application.
0
Attacker Value
Unknown
CVE-2024-46966
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.
0
Attacker Value
Unknown
CVE-2024-46964
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.
0
Attacker Value
Unknown
CVE-2024-46963
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.
0
Attacker Value
Unknown
CVE-2024-46962
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.
0
Attacker Value
Unknown
CVE-2024-46965
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.
0
Attacker Value
Unknown
CVE-2024-11078
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e/role leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10315
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.
0