Latest CVE Feed
-
7.3
HIGHCVE-2024-32391
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.... Read more
Affected Products : maccms- Published: Apr. 19, 2024
- Modified: Apr. 30, 2025
-
8.3
HIGHCVE-2024-29434
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.... Read more
Affected Products : alldata- Published: Apr. 02, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-29432
Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.... Read more
Affected Products : alldata- Published: Apr. 02, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-27602
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.... Read more
Affected Products : alldata- Published: Apr. 02, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-29368
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.... Read more
Affected Products : mozilocms- Published: Apr. 22, 2024
- Modified: Apr. 30, 2025
-
4.7
MEDIUMCVE-2024-30890
Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.... Read more
Affected Products : ed01-cms- Published: Apr. 25, 2024
- Modified: Apr. 30, 2025
-
5.0
MEDIUMCVE-2024-31574
Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script... Read more
Affected Products : twcms- Published: Apr. 25, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-39331
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.... Read more
Affected Products : emacs- Published: Jun. 23, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-45527
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.... Read more
Affected Products : redcap- Published: Sep. 02, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2025-30093
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.... Read more
Affected Products : htcondor- Published: Mar. 27, 2025
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-55072
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.... Read more
Affected Products : mealie- Published: Mar. 27, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-57519
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.... Read more
Affected Products : open5gs- Published: Jan. 28, 2025
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2024-48954
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2024-20021
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2024-42991
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.... Read more
Affected Products : mcms- Published: Sep. 03, 2024
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2024-20056
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; ... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2024-49200
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM varia... Read more
Affected Products : kernel- Published: Apr. 15, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2025-29088
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may... Read more
Affected Products : sqlite- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2024-20057
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-29017
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.... Read more
- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025