Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-21264

    Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker wi... Read more

    • Published: Oct. 15, 2024
    • Modified: Nov. 06, 2024
  • 5.3

    MEDIUM
    CVE-2024-21258

    Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via H... Read more

    Affected Products : installed_base
    • Published: Oct. 15, 2024
    • Modified: Nov. 06, 2024
  • 3.0

    LOW
    CVE-2024-21257

    Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical c... Read more

    Affected Products : hyperion_bi\+
    • Published: Oct. 15, 2024
    • Modified: Nov. 06, 2024
  • 8.1

    HIGH
    CVE-2024-21250

    Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low pri... Read more

    • Published: Oct. 15, 2024
    • Modified: Nov. 06, 2024
  • 4.3

    MEDIUM
    CVE-2024-21249

    Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to co... Read more

    • Published: Oct. 15, 2024
    • Modified: Nov. 06, 2024
  • 8.0

    HIGH
    CVE-2024-10841

    A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql inj... Read more

    Affected Products : web-sekolah
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 5.1

    MEDIUM
    CVE-2024-10840

    A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is ... Read more

    Affected Products : web-sekolah
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 5.1

    MEDIUM
    CVE-2024-10842

    A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Us... Read more

    Affected Products : web-sekolah
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10844

    A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the a... Read more

    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10845

    A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be ... Read more

    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 8.7

    HIGH
    CVE-2024-49370

    Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimc... Read more

    Affected Products : pimcore
    • Published: Oct. 23, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-49675

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii Bryl iBryl Switch User allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through 1.0.1.... Read more

    Affected Products : switch_user
    • Published: Oct. 23, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51683

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a t... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51682

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Element... Read more

    Affected Products : ht_builder
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51681

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.... Read more

    Affected Products : wp_pocket_urls
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51680

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.... Read more

    Affected Products : cresta_addons_for_elementor
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51678

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.... Read more

    Affected Products : elo_rating_shortcode
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51677

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.... Read more

    Affected Products : knowledge_base
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-51626

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.... Read more

    Affected Products : woocommerce_quote_calculator
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 7.6

    HIGH
    CVE-2024-51672

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more

    Affected Products : betterlinks
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
Showing 20 of 291170 Results