Latest CVE Feed
-
4.3
MEDIUMCVE-2024-45036
Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability allows Tophat to ... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
8.6
HIGHCVE-2024-43798
Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to set credentials, which allows any unauthenticated user to connect, even if credentials were set... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
7.7
HIGHCVE-2024-6379
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
- Published: Aug. 20, 2024
- Modified: Aug. 27, 2024
-
8.1
HIGHCVE-2024-6377
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.... Read more
- Published: Aug. 20, 2024
- Modified: Aug. 27, 2024
-
6.1
MEDIUMCVE-2024-42818
A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.3
MEDIUMCVE-2024-43319
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.... Read more
Affected Products : html5_video_player- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8140
A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting... Read more
Affected Products : task_progress_tracker- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8141
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to ... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8142
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross ... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8151
A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It... Read more
Affected Products : interactive_map_with_marker- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8154
A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_book... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8152
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argume... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8153
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site ... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8167
A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the atta... Read more
Affected Products : job_portal- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8168
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injectio... Read more
Affected Products : online_bus_reservation_site- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8169
A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be... Read more
Affected Products : online_quiz_site- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-7988
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which ... Read more
Affected Products : thinmanager_thinserver- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.5
HIGHCVE-2024-7987
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ servi... Read more
Affected Products : thinmanager_thinserver- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
10.0
CRITICALCVE-2024-5932
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible fo... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-41773
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.... Read more
Affected Products : global_configuration_management- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024