Latest CVE Feed
-
4.3
MEDIUMCVE-2024-21233
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-20463
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device. This vulnerability is due to the H... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
3.3
LOWCVE-2024-8013
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returne... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2024-50488
Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.... Read more
Affected Products : token_login- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-50483
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1.... Read more
Affected Products : meetup- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-50479
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.... Read more
Affected Products : woocommerce_quote_calculator- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-10449
A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initia... Read more
Affected Products : hospital_appointment_system- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2024-10230
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Oct. 22, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-50478
Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.... Read more
Affected Products : 1-click_login\- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50472
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Drapeau Amilia Store allows Stored XSS.This issue affects Amilia Store: from n/a through 2.9.8.... Read more
Affected Products : store- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50471
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Checklist Trip Plan allows Stored XSS.This issue affects Trip Plan: from n/a through 1.0.10.... Read more
Affected Products : trip_plan- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50470
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles allows Stored XSS.This issue affects Themes4WP YouTube External Subtitles: from n/a through 1.0.... Read more
Affected Products : youtube_external_subtitles- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
8.5
HIGHCVE-2024-50465
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.... Read more
Affected Products : premium_seo_pack- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2024-10447
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argu... Read more
Affected Products : online_time_table_generator- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
10.0
CRITICALCVE-2024-50498
Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console: from n/a through 1.0.... Read more
Affected Products : wp_query_console- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-50492
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart allows Code Injection.This issue affects ScottCart: from n/a through 1.1.... Read more
Affected Products : scottcart- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
5.3
MEDIUMCVE-2024-20526
A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for the SSH server of an affected device. This vulnerability is due to a ... Read more
Affected Products : adaptive_security_appliance_software- Published: Oct. 23, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50613
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.... Read more
Affected Products : libsndfile- Published: Oct. 27, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-10438
The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-10439
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024