Latest CVE Feed
-
4.8
MEDIUMCVE-2024-33867
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.5
MEDIUMCVE-2024-33866
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.9
MEDIUMCVE-2024-33864
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-48180
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.... Read more
Affected Products : classcms- Published: Oct. 16, 2024
- Modified: Apr. 28, 2025
-
7.5
HIGHCVE-2024-33865
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33863
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-30355
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-46101
GDidees CMS <= v3.9.1 has a file upload vulnerability.... Read more
Affected Products : gdidees_cms- Published: Sep. 20, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47218
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.... Read more
Affected Products : nebulagraph_database- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47219
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.... Read more
- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46084
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46082
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46080
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46083
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is importa... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
6.1
MEDIUMCVE-2024-46079
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46081
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to v... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
7.4
HIGHCVE-2025-21591
A Buffer Access with Incorrect Length Value vulnerability in the jdhcpd daemon of Juniper Networks Junos OS, when DHCP snooping is enabled, allows an unauthenticated, adjacent, attacker to send a DHCP packet with a malformed DHCP option to cause jdhcp to ... Read more
Affected Products : junos- Published: Apr. 09, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2024-55516
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-55515
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
6.3
MEDIUMCVE-2024-55514
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to u... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025