Latest CVE Feed
-
5.0
MEDIUMCVE-2024-31574
Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script... Read more
Affected Products : twcms- Published: Apr. 25, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-39331
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.... Read more
Affected Products : emacs- Published: Jun. 23, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-45527
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.... Read more
Affected Products : redcap- Published: Sep. 02, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2025-30093
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.... Read more
Affected Products : htcondor- Published: Mar. 27, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-55072
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.... Read more
Affected Products : mealie- Published: Mar. 27, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-57519
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.... Read more
Affected Products : open5gs- Published: Jan. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2024-48954
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2024-20021
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2024-42991
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.... Read more
Affected Products : mcms- Published: Sep. 03, 2024
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2024-20056
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; ... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2024-49200
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM varia... Read more
Affected Products : kernel- Published: Apr. 15, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2024-20057
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-29017
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.... Read more
- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2024-20058
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-22926
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Path Traversal
-
6.7
MEDIUMCVE-2024-20059
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-38985
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more
Affected Products : depath- Published: Mar. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2024-20060
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-37765
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37764
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025