Latest CVE Feed
-
6.5
MEDIUMCVE-2024-8143
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the use... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49641
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tidaweb Tida URL Screenshot allows Reflected XSS.This issue affects Tida URL Screenshot: from n/a through 1.0.... Read more
Affected Products : tida_url_screenshot- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49640
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AmaderCode Lab ACL Floating Cart for WooCommerce allows Reflected XSS.This issue affects ACL Floating Cart for WooCommerce: from n/a through 0.9.... Read more
Affected Products : acl_floating_cart_for_woocommerce- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49639
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Edward Stoever Monitor.Chat allows Reflected XSS.This issue affects Monitor.Chat: from n/a through 1.1.1.... Read more
Affected Products : monitor.chat- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48230
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49638
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali Azlan Risk Warning Bar allows Reflected XSS.This issue affects Risk Warning Bar: from n/a through 1.0.... Read more
Affected Products : risk_warning_bar- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48229
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-7783
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the passw... Read more
Affected Products : anythingllm- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-48227
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48223
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48222
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48218
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-48226
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.1
CRITICALCVE-2024-48225
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
5.0
MEDIUMCVE-2023-31310
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-48224
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49635
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manzurul Haque Banner Slider allows Reflected XSS.This issue affects Banner Slider: from n/a through 2.1.... Read more
Affected Products : banner_slider- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
5.3
MEDIUMCVE-2023-50355
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.... Read more
Affected Products : sametime- Published: Oct. 23, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2024-49980
In the Linux kernel, the following vulnerability has been resolved: vrf: revert "vrf: Remove unnecessary RCU-bh critical section" This reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853. dev_queue_xmit_nit is expected to be called with BH disabled... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2022-49000
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix PCI device refcount leak in has_external_pci() for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the refe... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 31, 2024