|
251501
|
6.1 |
MEDIUM
Network
|
fabianros
|
blood_bank_management_system
|
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bloodrequest.php. The …
|
CWE-79
Cross-site Scripting
|
CVE-2024-10419
|
2024-10-29 09:28 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251502
|
9.8 |
CRITICAL
Network
|
nurhodelta17
|
attendance_and_payroll_system
|
A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the file /marimar/guest/update.php. The manipulation of …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-10420
|
2024-10-29 09:21 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251503
|
9.8 |
CRITICAL
Network
|
nurhodelta17
|
attendance_and_payroll_system
|
A vulnerability classified as critical was found in SourceCodester Attendance and Payroll System 1.0. This vulnerability affects unknown code of the file /admin/overtime_row.php. The manipulation of …
|
CWE-89
SQL Injection
|
CVE-2024-10421
|
2024-10-29 09:19 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251504
|
9.8 |
CRITICAL
Network
|
nurhodelta17
|
attendance_and_payroll_system
|
A vulnerability, which was classified as critical, has been found in SourceCodester Attendance and Payroll System 1.0. This issue affects some unknown processing of the file /admin/overtime_add.php. …
|
CWE-89
SQL Injection
|
CVE-2024-10422
|
2024-10-29 09:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251505
|
8.8 |
HIGH
Network
|
yugeshverma
|
student_project_allocation_system
|
A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/project_selection/project_se…
|
CWE-89
SQL Injection
|
CVE-2024-10423
|
2024-10-29 09:08 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251506
|
5.3 |
MEDIUM
Network
|
drupal
|
drupal
|
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-45440
|
2024-10-29 06:35 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251507
|
6.8 |
MEDIUM
Adjacent
|
safie
|
qbic_cloud_cc-2\/2l_firmware safie_one_firmware
|
QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to obtain and/or alter communi…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-39771
|
2024-10-29 06:35 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251508
|
5.4 |
MEDIUM
Network
|
hp
|
poly_clariti_manager_firmware
|
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.
|
CWE-79
Cross-site Scripting
|
CVE-2024-41911
|
2024-10-29 06:35 |
2024-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251509
|
3.3 |
LOW
Local
|
rd_labs_llc
|
who
|
The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-40096
|
2024-10-29 06:35 |
2024-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251510
|
5.3 |
MEDIUM
Network
|
mecodia
|
feripro
|
An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding …
|
NVD-CWE-Other
|
CVE-2024-41517
|
2024-10-29 06:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|