Latest CVE Feed
-
6.1
MEDIUMCVE-2024-26473
A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php.... Read more
Affected Products : klik_socialmediawebsite- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-26472
KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selecto... Read more
Affected Products : klik_socialmediawebsite- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-26471
A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.... Read more
- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2024-26470
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.... Read more
Affected Products : .net_9_starter_kit- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-25846
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.... Read more
Affected Products : simpleimportproduct- Published: Feb. 27, 2024
- Modified: Apr. 30, 2025
-
6.8
MEDIUMCVE-2024-42768
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.... Read more
- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-42769
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
4.7
MEDIUMCVE-2024-42770
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.... Read more
- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2024-42771
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-42772
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-42773
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-42774
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-42775
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL a... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2024-42776
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2024-42767
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2025-43954
QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.... Read more
Affected Products : qmarkdown- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
8.4
HIGHCVE-2024-25388
drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.... Read more
Affected Products : rt-thread- Published: Mar. 27, 2024
- Modified: Apr. 30, 2025
-
8.4
HIGHCVE-2024-24335
A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.... Read more
Affected Products : rt-thread- Published: Mar. 27, 2024
- Modified: Apr. 30, 2025
-
8.4
HIGHCVE-2024-24334
A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.... Read more
Affected Products : rt-thread- Published: Mar. 27, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-23722
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.... Read more
Affected Products : fluent_bit- Published: Mar. 26, 2024
- Modified: Apr. 30, 2025