Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-51115

    DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.... Read more

    Affected Products :
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 6.6

    MEDIUM
    CVE-2024-34681

    Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.... Read more

    Affected Products : android
    • Published: Nov. 06, 2024
    • Modified: Nov. 06, 2024
  • 8.7

    HIGH
    CVE-2024-10082

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up until 6... Read more

    Affected Products :
    • Published: Nov. 06, 2024
    • Modified: Nov. 06, 2024
  • 1.8

    LOW
    CVE-2024-51746

    Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to ... Read more

    Affected Products : gitsign
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 4.8

    MEDIUM
    CVE-2024-20534

    A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (X... Read more

    Affected Products :
    • Published: Nov. 06, 2024
    • Modified: Nov. 06, 2024
  • 5.3

    MEDIUM
    CVE-2024-20445

    A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is ... Read more

    Affected Products :
    • Published: Nov. 06, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-6861

    A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire pro... Read more

    Affected Products : foreman
    • Published: Nov. 06, 2024
    • Modified: Nov. 06, 2024
  • 5.4

    MEDIUM
    CVE-2024-10753

    A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipul... Read more

    Affected Products : online_shopping_portal
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 8.1

    HIGH
    CVE-2024-51774

    qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.... Read more

    Affected Products : qbittorrent
    • Published: Nov. 02, 2024
    • Modified: Nov. 06, 2024
  • 4.0

    MEDIUM
    CVE-2024-47972

    Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.... Read more

    Affected Products :
    • Published: Oct. 07, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-45164

    Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality ... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10751

    A vulnerability was found in Codezips ISP Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file pay.php. The manipulation of the argument customer leads to sql injection. The attack may be launc... Read more

    Affected Products : isp_management_system
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 4.8

    MEDIUM
    CVE-2024-9883

    The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more

    Affected Products : pods
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-10502

    A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function getOneFileDirectory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument directory... Read more

    Affected Products : cdg
    • Published: Oct. 30, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-10501

    A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possibl... Read more

    Affected Products : cdg
    • Published: Oct. 30, 2024
    • Modified: Nov. 06, 2024
  • 4.3

    MEDIUM
    CVE-2024-9109

    The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.11. This make... Read more

    Affected Products : woocommerce_ups_shipping
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 7.4

    HIGH
    CVE-2024-47158

    N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.... Read more

    Affected Products : n-line
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-45785

    MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.... Read more

    Affected Products : musasi
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 10.0

    CRITICAL
    CVE-2024-50526

    Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more

    Affected Products : multi_purpose_mail_form
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 10.0

    CRITICAL
    CVE-2024-50527

    Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more

    Affected Products : stacks_mobile_app_builder
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
Showing 20 of 291150 Results