Latest CVE Feed
-
9.8
CRITICALCVE-2024-0947
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data ... Read more
Affected Products :- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6371
A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument rmtype_id l... Read more
Affected Products : pool_of_bethesda_online_reservation_system- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39376
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5751
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and assigns them to `os.e... Read more
Affected Products : litellm- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39208
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.... Read more
Affected Products :- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3816
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when... Read more
Affected Products : s\@m_cms- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38371
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an applicat... Read more
Affected Products : authentik- Published: Jun. 28, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-5827
Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor... Read more
Affected Products :- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39014
ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products :- Published: Jul. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39236
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself... Read more
Affected Products : gradio- Published: Jul. 01, 2024
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2024-37030
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6439
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestrict... Read more
Affected Products : home_owners_collection_management_system- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39864
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the inte... Read more
Affected Products : cloudstack- Published: Jul. 05, 2024
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2024-39677
NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types implementing ILiteralType.ObjectToSQLString. Callers of these methods are exposed to the vulnerability, which includes mappings using inhe... Read more
Affected Products : nhibernate-core- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6365
The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the lang... Read more
Affected Products : product_table- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39071
Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.... Read more
Affected Products :- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3680
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component LANG Command Handler. The manipulation leads to buffer overflow. The attack can be launched re... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2024-6396
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path... Read more
Affected Products : aim- Published: Jul. 12, 2024
- Modified: Jul. 23, 2025
-
9.8
CRITICALCVE-2024-5217
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the N... Read more
Affected Products : servicenow- Actively Exploited
- Published: Jul. 10, 2024
- Modified: Nov. 27, 2024
-
9.8
CRITICALCVE-2024-39914
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fi... Read more
Affected Products : fogproject- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024