Latest CVE Feed
-
5.4
MEDIUMCVE-2024-51495
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when e... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-51494
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
9.1
CRITICALCVE-2024-51164
Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-50724
KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Dec. 03, 2024
-
6.3
MEDIUMCVE-2024-50652
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.... Read more
Affected Products : java_shop- Published: Nov. 15, 2024
- Modified: Nov. 22, 2024
-
6.5
MEDIUMCVE-2024-50651
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.... Read more
Affected Products : java_shop- Published: Nov. 15, 2024
- Modified: Nov. 27, 2024
-
7.5
HIGHCVE-2024-50650
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.... Read more
Affected Products : python_book- Published: Nov. 15, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-50649
The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.... Read more
Affected Products : python_book- Published: Nov. 15, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-50648
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.... Read more
Affected Products : yshopmall- Published: Nov. 15, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2024-50647
The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Dec. 03, 2024
-
4.8
MEDIUMCVE-2024-50355
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside the ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50352
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50351
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "logs" tab of a device allows attackers to inject arbitrary JavaScript. This vulnerability r... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50350
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when creating ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-49764
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject arbitrary JavaScript through the "hostname" paramete... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-49759
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject arbitrary JavaScript through the "bill_name" parameter when... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
4.8
MEDIUMCVE-2024-49758
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the application did not properly sanitize the user input, when the ExamplePlugin enable, if java script code is inside the device's... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
7.5
HIGHCVE-2024-49754
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a ne... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
7.5
HIGHCVE-2024-41784
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitr... Read more
Affected Products : sterling_secure_proxy- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-11246
A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar-cliente.php. The manipulation of the argument nome/cpf/dataNascimento leads to cross site scripting. It i... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024