Latest CVE Feed
-
5.4
MEDIUMCVE-2024-10724
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue... Read more
Affected Products : phpipam- Published: Mar. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10725
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected ... Read more
Affected Products : phpipam- Published: Mar. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10719
A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerability allows an attacker to inject malicious scripts via the 'option' parameter in the POST request to /php... Read more
Affected Products : phpipam- Published: Mar. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-1813
A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been dis... Read more
Affected Products : zz- Published: Mar. 02, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
2.7
LOWCVE-2025-22212
A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend.... Read more
Affected Products : convert_forms- Published: Mar. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-12964
A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument user leads to sql injection. It is possible to i... Read more
Affected Products : daily_college_class_work_report_book- Published: Dec. 26, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-43158
Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.4.... Read more
Affected Products : masteriyo- Published: Nov. 01, 2024
- Modified: May. 28, 2025
-
5.3
MEDIUMCVE-2024-43159
Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.6.... Read more
Affected Products : masteriyo- Published: Nov. 01, 2024
- Modified: May. 28, 2025
-
5.3
MEDIUMCVE-2023-50904
Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.8.0.... Read more
Affected Products : poll_maker- Published: Dec. 09, 2024
- Modified: May. 28, 2025
-
5.3
MEDIUMCVE-2023-45766
Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.7.1.... Read more
Affected Products : poll_maker- Published: Jan. 02, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-12986
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. ... Read more
- Published: Dec. 27, 2024
- Modified: May. 28, 2025
-
6.5
MEDIUMCVE-2024-56295
Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 5.5.6.... Read more
Affected Products : poll_maker- Published: Jan. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-12988
A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to buffer overflow... Read more
- Published: Dec. 27, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-48814
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function... Read more
Affected Products : silverpeas- Published: Jan. 03, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26817
Netwrix Password Secure 9.2.0.32454 allows OS command injection.... Read more
Affected Products : password_secure- Published: Apr. 03, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-20076
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297806; Issue ID: MSV-... Read more
- Published: Jul. 01, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-13189
A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the att... Read more
Affected Products : myblog- Published: Jan. 08, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-20077
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297807; Issue ID: MSV-... Read more
- Published: Jul. 01, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-20078
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.... Read more
- Published: Jul. 01, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-20080
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch I... Read more
- Published: Jul. 01, 2024
- Modified: May. 28, 2025