Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2024-43376

    Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.... Read more

    Affected Products : umbraco_cms
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 8.7

    HIGH
    CVE-2024-7782

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function i... Read more

    Affected Products : contact_form_builder
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 7.2

    HIGH
    CVE-2024-7780

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient esca... Read more

    Affected Products : contact_form_builder
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 9.0

    CRITICAL
    CVE-2024-7777

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functio... Read more

    Affected Products : contact_form_builder
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 5.5

    MEDIUM
    CVE-2024-7775

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode functi... Read more

    Affected Products : contact_form_builder
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 7.2

    HIGH
    CVE-2024-7702

    The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient... Read more

    Affected Products : contact_form_builder
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-5941

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This make... Read more

    Affected Products : givewp
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 6.5

    MEDIUM
    CVE-2024-5940

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it po... Read more

    Affected Products : givewp
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 5.3

    MEDIUM
    CVE-2024-5939

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible f... Read more

    Affected Products : givewp
    • Published: Aug. 20, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-42766

    Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.... Read more

    Affected Products : bus_ticket_reservation_system
    • Published: Aug. 23, 2024
    • Modified: Aug. 26, 2024
  • 7.5

    HIGH
    CVE-2024-45241

    A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sens... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 4.9

    MEDIUM
    CVE-2024-43442

    Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other ad... Read more

    Affected Products : otrs
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 7.5

    HIGH
    CVE-2024-41996

    Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculation... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 8.1

    HIGH
    CVE-2024-39344

    An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be comp... Read more

    Affected Products :
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 7.8

    HIGH
    CVE-2024-7980

    Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more

    Affected Products : chrome windows edge_chromium
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 7.8

    HIGH
    CVE-2024-7979

    Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more

    Affected Products : chrome windows edge_chromium
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 8.8

    HIGH
    CVE-2024-7972

    Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)... Read more

    Affected Products : chrome edge_chromium
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 8.8

    HIGH
    CVE-2024-42786

    A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.... Read more

    Affected Products : music_management_system
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 8.8

    HIGH
    CVE-2024-42785

    A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more

    Affected Products : music_management_system
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-42784

    A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more

    Affected Products : music_management_system
    • Published: Aug. 21, 2024
    • Modified: Aug. 26, 2024
Showing 20 of 290162 Results