Latest CVE Feed
-
5.7
MEDIUMCVE-2024-51004
Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
5.7
MEDIUMCVE-2024-51002
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-46231
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit allows Cross Site Request Forgery. This issue affects affiliate-toolkit: from n/a through 3.7.3.... Read more
Affected Products : affiliate-toolkit- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-46232
Missing Authorization vulnerability in alttextai Download Alt Text AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Alt Text AI: from n/a through 1.9.93.... Read more
Affected Products : alt_text_ai- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2021-47192
In the Linux kernel, the following vulnerability has been resolved: scsi: core: sysfs: Fix hang when device state is set via sysfs This fixes a regression added with: commit f0f82e2476f6 ("scsi: core: Fix capacity set to zero after offlinining device")... Read more
Affected Products : linux_kernel- Published: Apr. 10, 2024
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2021-47262
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message Use the __string() machinery provided by the tracing subystem to make a copy of the string literals consumed by th... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2024-53920
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsa... Read more
Affected Products : emacs- Published: Nov. 27, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46233
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.... Read more
Affected Products : sirv- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-44739
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.... Read more
Affected Products : simple_forum_website- Published: Sep. 06, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-34833
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation o... Read more
- Published: Jun. 17, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-25239
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.... Read more
Affected Products : employee_management_system employee_management_system employee_management_system- Published: Mar. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2024-52945
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user t... Read more
Affected Products : netbackup- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-52944
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could r... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-52943
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This c... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-52942
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This c... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46235
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through ... Read more
Affected Products : skt_blocks- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-52922
In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complying with the peer-to-peer protocol specification.... Read more
Affected Products : bitcoin_core- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-52920
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.... Read more
Affected Products : bitcoin_core- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2024-52921
In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.... Read more
Affected Products : bitcoin_core- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2024-52919
Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.... Read more
Affected Products : bitcoin_core- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025