Latest CVE Feed
-
7.5
HIGHCVE-2024-25768
OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.... Read more
Affected Products : opendmarc- Published: Feb. 26, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-25767
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.... Read more
Affected Products : nanomq- Published: Feb. 26, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-48176
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into t... Read more
Affected Products : lylme_spage- Published: Nov. 05, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-35539
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.... Read more
Affected Products : typecho- Published: Aug. 19, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2023-7165
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.... Read more
Affected Products : jetbackup- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-33124
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..... Read more
Affected Products : roothub- Published: May. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-33120
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.... Read more
Affected Products : roothub- Published: May. 07, 2024
- Modified: May. 01, 2025
-
6.3
MEDIUMCVE-2024-33122
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.... Read more
Affected Products : roothub- Published: May. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-34088
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of serv... Read more
Affected Products : frrouting- Published: Apr. 30, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31951
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validate... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31950
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31949
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31948
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2023-7167
The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : persian_fonts- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-48743
Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.... Read more
Affected Products : sentry- Published: Oct. 25, 2024
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2023-7198
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant s... Read more
Affected Products : wp_dashboard_notes- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.... Read more
Affected Products : panels- Published: Apr. 09, 2025
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-10276
A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross... Read more
Affected Products : sentry- Published: Oct. 23, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31692
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.... Read more
- Published: Mar. 31, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31674
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, fr... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: May. 01, 2025