Latest CVE Feed
-
6.3
MEDIUMCVE-2024-33122
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.... Read more
Affected Products : roothub- Published: May. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-34088
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of serv... Read more
Affected Products : frrouting- Published: Apr. 30, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31951
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validate... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31950
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31949
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-31948
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.... Read more
Affected Products : frrouting- Published: Apr. 07, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2023-7167
The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : persian_fonts- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2024-48743
Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.... Read more
Affected Products : sentry- Published: Oct. 25, 2024
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2023-7198
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant s... Read more
Affected Products : wp_dashboard_notes- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.... Read more
Affected Products : panels- Published: Apr. 09, 2025
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-10276
A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross... Read more
Affected Products : sentry- Published: Oct. 23, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31692
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.... Read more
- Published: Mar. 31, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31674
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, fr... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2024-30202
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
5.5
MEDIUM- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
2.8
LOWCVE-2024-30204
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
7.1
HIGHCVE-2024-30205
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2023-7202
The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue... Read more
Affected Products : fatal_error_notify- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42586
A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42585
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025