Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.8

    MEDIUM
    CVE-2024-8166

    A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknown code of the file /tool/index.php?c=download&a=save. The manipulation of the argument content leads to unrestricted upload. The attack... Read more

    • Published: Aug. 26, 2024
    • Modified: Aug. 27, 2024
  • 6.5

    MEDIUM
    CVE-2024-43806

    Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator to "get stuck" when an IO error is encountered. Combined with a memory over-allocation issue in `rustix::fs... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 27, 2024
  • 4.3

    MEDIUM
    CVE-2024-6688

    The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated a... Read more

    Affected Products : oxygen
    • Published: Aug. 27, 2024
    • Modified: Aug. 27, 2024
  • 8.6

    HIGH
    CVE-2024-43798

    Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to set credentials, which allows any unauthenticated user to connect, even if credentials were set... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 27, 2024
  • 4.3

    MEDIUM
    CVE-2024-45036

    Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability allows Tophat to ... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 27, 2024
  • 6.4

    MEDIUM
    CVE-2024-8046

    The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escapi... Read more

    Affected Products :
    • Published: Aug. 27, 2024
    • Modified: Aug. 27, 2024
  • 6.4

    MEDIUM
    CVE-2024-7791

    The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the Post Grid widget in all versions up to, and including, 1.4.4.3 due to insufficient input sanitizatio... Read more

    Affected Products : xpro_addons_for_elementor
    • Published: Aug. 27, 2024
    • Modified: Aug. 27, 2024
  • 7.7

    HIGH
    CVE-2024-6379

    A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products : 3dexperience 3dexperience
    • Published: Aug. 20, 2024
    • Modified: Aug. 27, 2024
  • 8.1

    HIGH
    CVE-2024-6377

    An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.... Read more

    Affected Products : 3dexperience 3dexperience
    • Published: Aug. 20, 2024
    • Modified: Aug. 27, 2024
  • 6.1

    MEDIUM
    CVE-2024-42818

    A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.... Read more

    Affected Products :
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 4.3

    MEDIUM
    CVE-2024-43319

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.... Read more

    Affected Products : html5_video_player
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8140

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting... Read more

    Affected Products : task_progress_tracker
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8141

    A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to ... Read more

    Affected Products : daily_calories_monitoring_tool
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8142

    A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross ... Read more

    Affected Products : daily_calories_monitoring_tool
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8151

    A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It... Read more

    Affected Products : interactive_map_with_marker
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8154

    A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_book... Read more

    Affected Products : qr_code_bookmark_system
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8152

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argume... Read more

    Affected Products : qr_code_bookmark_system
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8153

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site ... Read more

    Affected Products : qr_code_bookmark_system
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-8167

    A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the atta... Read more

    Affected Products : job_portal
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-8168

    A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injectio... Read more

    Affected Products : online_bus_reservation_site
    • Published: Aug. 26, 2024
    • Modified: Aug. 26, 2024
Showing 20 of 291562 Results