Latest CVE Feed
-
9.8
CRITICALCVE-2024-10766
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrest... Read more
Affected Products : free_exam_hall_seating_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51132
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51115
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51358
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
9.8
CRITICALCVE-2024-10919
A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. The manipulation of the argument uuid leads to os command injection. The atta... Read more
Affected Products : super-jacoco- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-10969
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/login_process.php of the component Login. The manipulation of the argument u... Read more
Affected Products : bookstore_management_system- Published: Nov. 07, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2024-50588
An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among ... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-11047
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer ... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-11016
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products : webopac- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-51135
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-11100
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument name leads to sql inject... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52297
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.... Read more
Affected Products : tolgee- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-11209
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotel... Read more
Affected Products : central_authentication_service- Published: Nov. 14, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11237
A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to s... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11250
A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /model/editProduct.php. The manipulation of the argument id leads to sql injection. The attack... Read more
Affected Products : inventory_management- Published: Nov. 15, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2024-44758
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 27, 2024
-
9.8
CRITICALCVE-2024-8856
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21... Read more
Affected Products : backup_and_staging_by_wp_time_capsule- Published: Nov. 16, 2024
- Modified: Jul. 09, 2025
-
9.8
CRITICALCVE-2024-52410
Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector allows Object Injection.This issue affects Referrer Detector: from n/a through 4.2.1.0.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52414
Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through 5.3.18.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-11314
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024