Latest CVE Feed
-
7.2
HIGHCVE-2024-50832
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50831
A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50830
A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50829
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50828
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50827
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2024-42499
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
4.8
MEDIUMCVE-2024-45087
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di... Read more
Affected Products : websphere_application_server- Published: Nov. 11, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-45088
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di... Read more
Affected Products : maximo_asset_management- Published: Nov. 11, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-50323
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-50322
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-48073
sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-37398
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : secure_access_client- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
4.9
MEDIUMCVE-2024-47909
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-47907
A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : connect_secure- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
4.9
MEDIUMCVE-2024-47905
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50318
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50317
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50321
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50320
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024