Latest CVE Feed
-
8.8
HIGHCVE-2024-57775
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-57774
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
-
4.8
MEDIUMCVE-2024-57773
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57772
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57771
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57770
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-57769
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57768
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
0.0
NONECVE-2024-50633
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentiona... Read more
Affected Products : indico- Published: Jan. 16, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-41746
IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d... Read more
- Published: Jan. 16, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
2.6
LOWCVE-2024-37181
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Race Condition
-
5.3
MEDIUMCVE-2025-0518
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue a... Read more
Affected Products : ffmpeg- Published: Jan. 16, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Memory Corruption
-
3.5
LOWCVE-2024-57611
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.2
HIGHCVE-2024-57162
Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.... Read more
Affected Products : cybercafe_management_system- Published: Jan. 16, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-57161
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-57160
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2024-57159
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-0473
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoi... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-0472
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Information Disclosure
-
9.9
CRITICALCVE-2025-0471
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication