Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.2

    HIGH
    CVE-2024-32762

    A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuLog Center... Read more

    Affected Products : qulog_center
    • Published: Sep. 06, 2024
    • Modified: Sep. 13, 2024
  • 7.5

    HIGH
    CVE-2024-42036

    Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more

    Affected Products : emui harmonyos
    • Published: Aug. 08, 2024
    • Modified: Sep. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-43132

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / ... Read more

    Affected Products : docket
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 4.8

    MEDIUM
    CVE-2024-27125

    A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following ver... Read more

    Affected Products : helpdesk
    • Published: Sep. 06, 2024
    • Modified: Sep. 13, 2024
  • 7.6

    HIGH
    CVE-2024-39658

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7.... Read more

    Affected Products : salon_booking_system
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-39653

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.... Read more

    Affected Products : vikrentcar
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-39638

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.... Read more

    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-38793

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.... Read more

    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-38486

    Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potent... Read more

    Affected Products : smartfabric_os10
    • Published: Sep. 06, 2024
    • Modified: Sep. 13, 2024
  • 7.6

    HIGH
    CVE-2024-38693

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.... Read more

    Affected Products : wp_user_frontend
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 9.2

    CRITICAL
    CVE-2024-1744

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.... Read more

    Affected Products : accord_ors
    • Published: Sep. 06, 2024
    • Modified: Sep. 13, 2024
  • 6.1

    MEDIUM
    CVE-2024-5624

    Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session... Read more

    Affected Products : industrial_automation_aprol
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 7.8

    HIGH
    CVE-2024-5622

    An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.... Read more

    Affected Products : industrial_automation_aprol
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 7.8

    HIGH
    CVE-2024-5623

    An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.... Read more

    Affected Products : industrial_automation_aprol
    • Published: Aug. 29, 2024
    • Modified: Sep. 13, 2024
  • 8.8

    HIGH
    CVE-2024-45059

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.p... Read more

    Affected Products : i-educar
    • Published: Aug. 28, 2024
    • Modified: Sep. 13, 2024
  • 8.1

    HIGH
    CVE-2024-45058

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to chang... Read more

    Affected Products : i-educar
    • Published: Aug. 28, 2024
    • Modified: Sep. 13, 2024
  • 6.3

    MEDIUM
    CVE-2024-45057

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the dynamic generation of HTML fields prior... Read more

    Affected Products : i-educar
    • Published: Aug. 28, 2024
    • Modified: Sep. 13, 2024
  • 7.5

    HIGH
    CVE-2024-45442

    Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.... Read more

    Affected Products : emui harmonyos
    • Published: Sep. 04, 2024
    • Modified: Sep. 13, 2024
  • 6.3

    MEDIUM
    CVE-2024-43797

    audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows a pat... Read more

    Affected Products : audiobookshelf
    • Published: Sep. 02, 2024
    • Modified: Sep. 13, 2024
  • 9.8

    CRITICAL
    CVE-2024-7261

    The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlie... Read more

    • Published: Sep. 03, 2024
    • Modified: Sep. 13, 2024
Showing 20 of 292792 Results