Latest CVE Feed
-
5.4
MEDIUMCVE-2024-51495
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when e... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-52526
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-11247
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Inventory Page. The man... Read more
Affected Products : online_eyewear_shop- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2024-51142
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.... Read more
Affected Products : chamilo_lms- Published: Nov. 15, 2024
- Modified: Apr. 18, 2025
-
5.4
MEDIUMCVE-2024-52943
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This c... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-47424
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2024-52763
A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "g" parameter.... Read more
Affected Products : ganglia-web- Published: Nov. 19, 2024
- Modified: Nov. 29, 2024
-
5.4
MEDIUMCVE-2024-45691
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" v... Read more
Affected Products : moodle- Published: Nov. 20, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-32468
Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the `deno_doc` crate which lead to Self-XSS with deno doc --html. 1.) XSS in generated `search_index.js`, `deno_doc` outputs a JavaScr... Read more
Affected Products : deno- Published: Nov. 25, 2024
- Modified: Nov. 25, 2024
-
5.4
MEDIUMCVE-2024-11677
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php of the component Add Vendor Details Page. The manipulation of th... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2024-11820
A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file /add.php. The manipulation of the argument saddress leads to cross site scripting. The ... Read more
Affected Products : crud_operation_system- Published: Nov. 27, 2024
- Modified: Dec. 03, 2024
-
5.4
MEDIUMCVE-2024-10473
The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripti... Read more
- Published: Nov. 28, 2024
- Modified: May. 15, 2025
-
5.4
MEDIUMCVE-2024-10493
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is... Read more
Affected Products : element_pack- Published: Nov. 28, 2024
- Modified: May. 15, 2025
-
5.4
MEDIUMCVE-2024-10896
The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting... Read more
- Published: Nov. 28, 2024
- Modified: May. 15, 2025
-
5.4
MEDIUMCVE-2024-36625
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
5.4
MEDIUMCVE-2024-53364
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.... Read more
Affected Products : vehicle_parking_management_system- Published: Dec. 02, 2024
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2024-52676
Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php.... Read more
- Published: Dec. 04, 2024
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2024-12094
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2024-12181
A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to c... Read more
Affected Products : dedecms- Published: Dec. 04, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2024-12359
A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The a... Read more
Affected Products : admin_dashboard- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024