Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2024-42771

    A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-42772

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-42773

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-42774

    An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-42775

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL a... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2024-42776

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2024-42767

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2025-43954

    QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.... Read more

    Affected Products : qmarkdown
    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 8.4

    HIGH
    CVE-2024-25388

    drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.... Read more

    Affected Products : rt-thread
    • Published: Mar. 27, 2024
    • Modified: Apr. 30, 2025
  • 8.4

    HIGH
    CVE-2024-24335

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.... Read more

    Affected Products : rt-thread
    • Published: Mar. 27, 2024
    • Modified: Apr. 30, 2025
  • 8.4

    HIGH
    CVE-2024-24334

    A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.... Read more

    Affected Products : rt-thread
    • Published: Mar. 27, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-23722

    In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.... Read more

    Affected Products : fluent_bit
    • Published: Mar. 26, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-29644

    Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.... Read more

    Affected Products : dcat_admin
    • Published: Mar. 26, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-32418

    An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.... Read more

    Affected Products : flusity
    • Published: Apr. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.3

    HIGH
    CVE-2024-32391

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.... Read more

    Affected Products : maccms
    • Published: Apr. 19, 2024
    • Modified: Apr. 30, 2025
  • 8.3

    HIGH
    CVE-2024-29434

    An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.... Read more

    Affected Products : alldata
    • Published: Apr. 02, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-29432

    Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.... Read more

    Affected Products : alldata
    • Published: Apr. 02, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-27602

    Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.... Read more

    Affected Products : alldata
    • Published: Apr. 02, 2024
    • Modified: Apr. 30, 2025
  • 6.5

    MEDIUM
    CVE-2024-29368

    An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.... Read more

    Affected Products : mozilocms
    • Published: Apr. 22, 2024
    • Modified: Apr. 30, 2025
  • 4.7

    MEDIUM
    CVE-2024-30890

    Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.... Read more

    Affected Products : ed01-cms
    • Published: Apr. 25, 2024
    • Modified: Apr. 30, 2025
Showing 20 of 291124 Results