Latest CVE Feed
-
6.5
MEDIUMCVE-2024-20482
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected device. To e... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
9.0
CRITICALCVE-2024-6581
A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, ... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-49400
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-46903
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code... Read more
Affected Products : deep_discovery_inspector- Published: Oct. 22, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-8309
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deletin... Read more
Affected Products : langchain- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.1
HIGHCVE-2024-49660
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Campus Explorer Campus Explorer Widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through 1.4.... Read more
Affected Products : widget- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.1
HIGHCVE-2024-49661
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lew Ayotte leenk.Me allows Reflected XSS.This issue affects leenk.Me: from n/a through 2.16.0.... Read more
Affected Products : leenk.me- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.1
HIGHCVE-2024-49662
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webgensis Simple Load More allows Reflected XSS.This issue affects Simple Load More: from n/a through 1.0.... Read more
Affected Products : simple_load_more- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.1
HIGHCVE-2024-49663
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elena Zhyvohliad uCAT – Next Story allows Reflected XSS.This issue affects uCAT – Next Story: from n/a through 2.0.0.... Read more
Affected Products : ucat- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-49665
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web Bricks Web Bricks Addons for Elementor allows Stored XSS.This issue affects Web Bricks Addons for Elementor: from n/a through 1.1.1.... Read more
Affected Products : web_bricks_addons- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-49667
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NervyThemes Local Business Addons For Elementor allows Stored XSS.This issue affects Local Business Addons For Elementor: from n/a through 1.1.5.... Read more
Affected Products : local_business_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-9361
The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0... Read more
Affected Products : bulk_images_optimizer- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-10119
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.... Read more
- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
6.9
MEDIUMCVE-2024-10448
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads to cross-... Read more
- Published: Oct. 28, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-10040
The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_ajax_edit and process_ajax_delete function. This makes it... Read more
Affected Products : infinite-scroll- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20472
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20471
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20474
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer und... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20473
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
9.9
CRITICALCVE-2024-20424
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying o... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024