Show filters
8,318 Total Results
Displaying 321-330 of 8,318
Sort by:
Attacker Value
Unknown

CVE-2024-50652

Disclosure Date: November 15, 2024 (last updated February 27, 2025)
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.
Attacker Value
Unknown

CVE-2024-50651

Disclosure Date: November 15, 2024 (last updated February 27, 2025)
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
Attacker Value
Unknown

CVE-2024-11120

Disclosure Date: November 15, 2024 (last updated February 27, 2025)
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Attacker Value
Unknown

CVE-2024-51659

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus allows Stored XSS.This issue affects Twitter @Anywhere Plus: from n/a through 2.0.
0
Attacker Value
Unknown

CVE-2024-50968

Disclosure Date: November 14, 2024 (last updated November 16, 2024)
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.
Attacker Value
Unknown

CVE-2024-52384

Disclosure Date: November 14, 2024 (last updated February 27, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in Sage AI Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation allows Upload a Web Shell to a Web Server.This issue affects Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation: from n/a through 2.4.9.
0
Attacker Value
Unknown

CVE-2024-49379

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can specify a malicious redirect query parameter to trigger the vulnerability. If a JavaScript URL is passed to the redirect parameter the attacker provided JavaScript will be executed after the user entered their password and clicked on login. This vulnerability is fixed in 1.2.2.
0
Attacker Value
Unknown

CVE-2024-50972

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
Attacker Value
Unknown

CVE-2024-50971

Disclosure Date: November 13, 2024 (last updated February 27, 2025)
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
Attacker Value
Unknown

CVE-2024-52297

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.
0