Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2024-9807

    A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scri... Read more

    Affected Products : classroombookings
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 5.3

    MEDIUM
    CVE-2024-9806

    A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross ... Read more

    Affected Products : classroombookings
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 8.4

    HIGH
    CVE-2024-47962

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to ex... Read more

    Affected Products : cncsoft-g2
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 8.4

    HIGH
    CVE-2024-47963

    Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code ... Read more

    Affected Products : cncsoft-g2
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 8.4

    HIGH
    CVE-2024-47964

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute ... Read more

    Affected Products : cncsoft-g2
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 8.4

    HIGH
    CVE-2024-47965

    Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code i... Read more

    Affected Products : cncsoft-g2
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 8.4

    HIGH
    CVE-2024-47966

    Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.... Read more

    Affected Products : cncsoft-g2
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 6.1

    MEDIUM
    CVE-2024-9799

    A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/... Read more

    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 4.3

    MEDIUM
    CVE-2024-39586

    Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.... Read more

    Affected Products : emc_appsync appsync
    • Published: Oct. 09, 2024
    • Modified: Oct. 17, 2024
  • 7.2

    HIGH
    CVE-2024-9790

    A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The e... Read more

    Affected Products : lylme_spage
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 7.2

    HIGH
    CVE-2024-9789

    A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The explo... Read more

    Affected Products : lylme_spage
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 7.2

    HIGH
    CVE-2024-9788

    A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The explo... Read more

    Affected Products : lylme_spage
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 5.4

    MEDIUM
    CVE-2024-7049

    In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.... Read more

    Affected Products : open_webui
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 7.8

    HIGH
    CVE-2024-9780

    ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file... Read more

    Affected Products : wireshark
    • Published: Oct. 10, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    HIGH
    CVE-2024-46865

    In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 17, 2024
  • 7.8

    HIGH
    CVE-2024-46859

    In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses The panasonic laptop code in various places uses the SINF array with index values of 0 - SINF_CUR_BRIGHT(0x0d) with... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 17, 2024
  • 4.7

    MEDIUM
    CVE-2024-46710

    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to read and compare the cursor buffer. These maps can race with each other in simple scenari... Read more

    Affected Products : linux_kernel
    • Published: Sep. 13, 2024
    • Modified: Oct. 17, 2024
  • 4.4

    MEDIUM
    CVE-2024-46695

    In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS f... Read more

    Affected Products : linux_kernel
    • Published: Sep. 13, 2024
    • Modified: Oct. 17, 2024
  • 5.5

    MEDIUM
    CVE-2023-52904

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix possible NULL pointer dereference in snd_usb_pcm_has_fixed_rate() The subs function argument may be NULL, so do not use it before the NULL check.... Read more

    Affected Products : linux_kernel
    • Published: Aug. 21, 2024
    • Modified: Oct. 17, 2024
  • 7.1

    HIGH
    CVE-2024-45060

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading t... Read more

    Affected Products : phpexcel phpspreadsheet
    • Published: Oct. 07, 2024
    • Modified: Oct. 17, 2024
Showing 20 of 291385 Results