Show filters
1,913 Total Results
Displaying 481-490 of 1,913
Sort by:
Attacker Value
Unknown

CVE-2024-48700

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
0
Attacker Value
Unknown

CVE-2024-48655

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
0
Attacker Value
Unknown

CVE-2024-48581

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
0
Attacker Value
Unknown

CVE-2024-48579

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
0
Attacker Value
Unknown

CVE-2024-48204

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.
0
Attacker Value
Unknown

CVE-2024-47158

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.
Attacker Value
Unknown

CVE-2024-47879

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled expression to be executed. The expression can contain arbitrary Clojure or Python code. The attacker must know a valid project ID of a project that contains at least one row, and the attacker must convince the victim to open a malicious webpage. Version 3.8.3 fixes the issue.
Attacker Value
Unknown

CVE-2024-48514

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.
0
Attacker Value
Unknown

CVE-2024-48964

Disclosure Date: October 23, 2024 (last updated February 26, 2025)
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk recommends only scanning trusted projects.
Attacker Value
Unknown

CVE-2024-20485

Disclosure Date: October 23, 2024 (last updated February 26, 2025)
A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a specific file when it is read from system flash memory. An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.