Latest CVE Feed
-
5.4
MEDIUMCVE-2024-5941
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This make... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-5940
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it po... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.3
MEDIUMCVE-2024-5939
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible f... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-42766
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.... Read more
Affected Products : bus_ticket_reservation_system- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-45241
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sens... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.9
MEDIUMCVE-2024-43442
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other ad... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-41996
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculation... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.1
HIGHCVE-2024-39344
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be comp... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7980
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7979
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-7972
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42786
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42785
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-42784
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
4.1
MEDIUMCVE-2024-41849
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41848
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41847
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41846
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-45258
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.... Read more
Affected Products :- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
7.3
HIGHCVE-2024-43688
cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.... Read more
- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024