Latest CVE Feed
-
9.8
CRITICALCVE-2024-6113
A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument email leads to sql injection. Th... Read more
Affected Products : monbela_tourist_inn_online_reservation_system- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6190
A vulnerability was found in itsourcecode Farm Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql ... Read more
- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6009
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The ... Read more
Affected Products : learning_management_system_project_in_php_with_source_code- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6016
A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql inje... Read more
Affected Products : laundry_management_system_project_in_php_with_source_code- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5894
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated rem... Read more
- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5983
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file bookPerPub.php. The manipulation of the argument pubid leads to sql injection. The att... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5701
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.... Read more
Affected Products : firefox- Published: Jun. 11, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-5695
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.... Read more
Affected Products : firefox- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5357
A vulnerability has been found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injec... Read more
Affected Products : zoo_management_system- Published: May. 26, 2024
- Modified: Feb. 21, 2025
-
9.8
CRITICALCVE-2024-5352
A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules of the component com.anjiplus.template.gaea.business.modules.datasetparam.controller.DataSetParamController... Read more
- Published: May. 26, 2024
- Modified: Mar. 01, 2025
-
9.8
CRITICALCVE-2024-5436
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.... Read more
Affected Products : snapchat_lenscore- Published: May. 31, 2024
- Modified: Jul. 22, 2025
-
9.8
CRITICALCVE-2024-5122
A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registrar/. The manipulation of the argument search leads to sql injection. The att... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-5150
The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in the 'lwp_ajax_register' fu... Read more
Affected Products : login_with_phone_number- Published: May. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-58136
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.... Read more
Affected Products : yii- Actively Exploited
- Published: Apr. 10, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-58266
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.... Read more
Affected Products : shlex- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-5085
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthentica... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Mar. 01, 2025
-
9.8
CRITICALCVE-2024-57959
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57961
Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57687
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.... Read more
Affected Products : land_record_system- Published: Jan. 10, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57703
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.... Read more
- Published: Jan. 16, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption