Latest CVE Feed
-
8.8
HIGHCVE-2024-6988
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.5
HIGHCVE-2024-41990
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.... Read more
Affected Products : django- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
7.5
HIGHCVE-2024-41991
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of U... Read more
Affected Products : django- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7580
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/system.html. The manipulation of the argument uploadedFile with the input ;who... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6995
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromiu... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
6.5
MEDIUMCVE-2024-7564
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required... Read more
Affected Products : unified_secops_platform- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7581
A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security leads to stack-based buffer overflow. It is possible to... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7005
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium sec... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
4.3
MEDIUMCVE-2024-7003
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6998
Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6997
Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
5.4
MEDIUMCVE-2024-7368
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scri... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7369
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads t... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7370
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the argument id leads to sql injection. It is possible to la... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7371
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quiz_view.php. The manipulation of the argument id leads to sql injectio... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7372
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /quiz_board.php. The manipulation of the argument quiz leads to sql injection. The... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7373
A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-33974
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7441
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-b... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 07, 2024
-
5.4
MEDIUMCVE-2024-7353
The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on use... Read more
Affected Products :- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024