Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-25164

    iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.... Read more

    Affected Products : idurar idurar
    • Published: Mar. 05, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2024-27516

    Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.... Read more

    Affected Products : live_helper_chat livehelperchat
    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-26473

    A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php.... Read more

    Affected Products : klik_socialmediawebsite
    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-26472

    KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selecto... Read more

    Affected Products : klik_socialmediawebsite
    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 5.4

    MEDIUM
    CVE-2024-26471

    A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.... Read more

    Affected Products : ibarn klik_socialmediawebsite
    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 8.1

    HIGH
    CVE-2024-26470

    A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.... Read more

    Affected Products : .net_9_starter_kit
    • Published: Feb. 29, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-25846

    In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.... Read more

    Affected Products : simpleimportproduct
    • Published: Feb. 27, 2024
    • Modified: Apr. 30, 2025
  • 6.8

    MEDIUM
    CVE-2024-42768

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.... Read more

    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2024-42769

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 4.7

    MEDIUM
    CVE-2024-42770

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.... Read more

    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2024-42771

    A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-42772

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-42773

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.5

    HIGH
    CVE-2024-42774

    An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2024-42775

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL a... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2024-42776

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 7.2

    HIGH
    CVE-2024-42767

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.... Read more

    Affected Products : hotel_management_system
    • Published: Aug. 22, 2024
    • Modified: Apr. 30, 2025
  • 6.1

    MEDIUM
    CVE-2025-43954

    QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.... Read more

    Affected Products : qmarkdown
    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 8.4

    HIGH
    CVE-2024-25388

    drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.... Read more

    Affected Products : rt-thread
    • Published: Mar. 27, 2024
    • Modified: Apr. 30, 2025
  • 8.4

    HIGH
    CVE-2024-24335

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.... Read more

    Affected Products : rt-thread
    • Published: Mar. 27, 2024
    • Modified: Apr. 30, 2025
Showing 20 of 291150 Results