Latest CVE Feed
-
8.8
HIGHCVE-2024-41679
GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to 10.0.17.... Read more
Affected Products : glpi- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-43417
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability located in the Software form. Upgrade to 10.0.17.... Read more
Affected Products : glpi- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-43418
GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17.... Read more
Affected Products : glpi- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
8.8
HIGHCVE-2024-45608
GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.... Read more
Affected Products : glpi- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-52419
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Clipboard Team Copy Anything to Clipboard allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through 4.0.3.... Read more
Affected Products : copy_anything_to_clipboard- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
6.2
MEDIUMCVE-2024-11308
The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
7.5
HIGHCVE-2024-11309
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
7.5
HIGHCVE-2024-11310
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11311
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11312
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11313
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11314
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11315
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.... Read more
Affected Products : dvc- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.6
CRITICALCVE-2024-52401
Cross-Site Request Forgery (CSRF) vulnerability in 荒野无灯 Hacklog DownloadManager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through 2.1.4.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-51814
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 野人 活动链接推广插件 allows DOM-Based XSS.This issue affects 活动链接推广插件: from n/a through 1.2.0.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-52422
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Terry Lin WP Githuber MD allows Stored XSS.This issue affects WP Githuber MD: from n/a through 1.16.3.... Read more
Affected Products : wp_githuber_md- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
4.3
MEDIUMCVE-2024-7836
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Cont... Read more
- Published: Aug. 22, 2024
- Modified: Nov. 20, 2024
-
6.1
MEDIUMCVE-2024-11240
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. The manipulation of the argument db_login_role leads to ... Read more
Affected Products : ibwebadmin- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
9.6
CRITICALCVE-2024-52308
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remot... Read more
Affected Products : cli- Published: Nov. 14, 2024
- Modified: Nov. 20, 2024
-
7.5
HIGHCVE-2024-49754
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the "token" parameter when creating a ne... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024