Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2024-10122

    A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the component Operator Details Form. The manipulation leads to missing password fi... Read more

    Affected Products : inner_rep_plus
    • Published: Oct. 18, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-48050

    In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.... Read more

    Affected Products :
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-49223

    Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.K.A CyberJack CJ Change Howdy allows Stored XSS.This issue affects CJ Change Howdy: from n/a through 3.3.1.... Read more

    Affected Products : cj_change_howdy
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-49221

    Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored XSS.This issue affects cSlider: from n/a through 2.4.2.... Read more

    Affected Products : cslider
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-49217

    Incorrect Privilege Assignment vulnerability in Madiri Salman Aashish Adding drop down roles in registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through 1.1.... Read more

    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-49219

    Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3.... Read more

    Affected Products : rs-members
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-49220

    Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.... Read more

    Affected Products : cookie_scanner
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-49229

    Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.... Read more

    Affected Products : better_author_bio
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-31880

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.... Read more

    Affected Products : linux_kernel db2 windows unix
    • Published: Oct. 23, 2024
    • Modified: Nov. 06, 2024
  • 6.5

    MEDIUM
    CVE-2024-51362

    The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network ... Read more

    Affected Products :
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 8.0

    HIGH
    CVE-2024-51240

    An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package... Read more

    Affected Products :
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-51132

    An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.... Read more

    Affected Products :
    • Published: Nov. 05, 2024
    • Modified: Nov. 06, 2024
  • 7.7

    HIGH
    CVE-2024-42018

    An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to t... Read more

    Affected Products :
    • Published: Oct. 11, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-39339

    A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, he... Read more

    Affected Products :
    • Published: Sep. 18, 2024
    • Modified: Nov. 06, 2024
  • 7.1

    HIGH
    CVE-2024-49237

    Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.... Read more

    Affected Products : ahmeti_wp_timeline
    • Published: Oct. 17, 2024
    • Modified: Nov. 06, 2024
  • 5.9

    MEDIUM
    CVE-2024-51685

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.... Read more

    Affected Products : accordion_title_for_elementor
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-48809

    An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function.... Read more

    Affected Products : onos-a1t sdran-in-a-box
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-51136

    An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.... Read more

    Affected Products : openimaj
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.8

    MEDIUM
    CVE-2024-34882

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.... Read more

    Affected Products : bitrix24
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.8

    MEDIUM
    CVE-2024-34883

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.... Read more

    Affected Products : bitrix24
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
Showing 20 of 291205 Results