Show filters
13,153 Total Results
Displaying 351-360 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2022-4002

Disclosure Date: July 31, 2024 (last updated August 14, 2024)
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
Attacker Value
Unknown

CVE-2024-31201

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
Attacker Value
Unknown

CVE-2024-39946

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.
Attacker Value
Unknown

CVE-2024-39945

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.
Attacker Value
Unknown

CVE-2024-7278

Disclosure Date: July 31, 2024 (last updated August 09, 2024)
A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_save.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273147.
Attacker Value
Unknown

CVE-2024-7277

Disclosure Date: July 31, 2024 (last updated August 09, 2024)
A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/menu.php of the component Add a Menu. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273146 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-7276

Disclosure Date: July 30, 2024 (last updated August 09, 2024)
A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/member_save.php. The manipulation of the argument last/first leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273145 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-7275

Disclosure Date: July 30, 2024 (last updated August 14, 2024)
A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273144.
Attacker Value
Unknown

CVE-2024-7274

Disclosure Date: July 30, 2024 (last updated August 14, 2024)
A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issue affects some unknown processing of the file /reservation_status.php. The manipulation of the argument rcode leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273143.
Attacker Value
Unknown

CVE-2024-41305

Disclosure Date: July 30, 2024 (last updated August 09, 2024)
A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.