Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
28020.4%CRITICAL

Related CVEs

8
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-50650python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.HIGH7.541.5%Nov 15, 2024
CVE-2024-50649The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.CRITICAL9.857.1%Nov 15, 2024
CVE-2024-50966dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.CRITICAL9.316.6%Nov 8, 2024
CVE-2024-48291dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17MEDIUM6.36.7%Oct 28, 2024
CVE-2024-48191dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17MEDIUM6.37.1%Oct 28, 2024
CVE-2024-48758dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary codeMEDIUM6.116.9%Oct 16, 2024
CVE-2024-46600dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31MEDIUM4.710.4%Sep 25, 2024
CVE-2024-46485dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCateMEDIUM6.36.7%Sep 25, 2024