Latest CVE Feed
-
9.8
CRITICALCVE-2024-9038
A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimag... Read more
Affected Products : online_shopping_portal- Published: Sep. 20, 2024
- Modified: Sep. 27, 2024
-
9.8
CRITICALCVE-2024-42507
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-9090
A vulnerability was found in SourceCodester Modern Loan Management System 1.0. It has been classified as critical. Affected is an unknown function of the file search_member.php. The manipulation of the argument searchMember leads to sql injection. It is p... Read more
Affected Products : modern_loan_management_system- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
9.8
CRITICALCVE-2024-7781
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in ... Read more
- Published: Sep. 26, 2024
- Modified: Oct. 02, 2024
-
9.8
CRITICALCVE-2024-46628
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.... Read more
- Published: Sep. 26, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-8643
Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0.... Read more
Affected Products : valeapp- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9318
A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9326
A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to sql i... Read more
- Published: Sep. 29, 2024
- Modified: Oct. 02, 2024
-
9.8
CRITICALCVE-2024-44097
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to int... Read more
Affected Products : android nest_doorbell_\(battery\)_firmware nest_doorbell_\(battery\) nest_cam_\(outdoor_or_indoor\,_battery\)_firmware nest_cam_\(outdoor_or_indoor\,_battery\) nest_cam_with_floodlight_firmware nest_cam_with_floodlight nest_cam_\(indoor\,_wired\)_firmware nest_cam_\(indoor\,_wired\)- Published: Oct. 02, 2024
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2024-24116
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.... Read more
- Published: Oct. 02, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-33066
Memory corruption while redirecting log file to any file location with any file name.... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-8943
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthent... Read more
Affected Products : latepoint- Published: Oct. 08, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2024-8884
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-44349
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-45402
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may attempt to free ... Read more
- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-46532
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-48033
Deserialization of Untrusted Data vulnerability in Elie Burstein, Baptiste Gourdin Talkback allows Object Injection.This issue affects Talkback: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-48251
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.... Read more
Affected Products : wavelog- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
9.8
CRITICALCVE-2024-48283
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Oct. 15, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-48779
An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 17, 2024