Latest CVE Feed
-
7.7
HIGHCVE-2024-42457
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credent... Read more
Affected Products : veeam_backup_\&_replication- Published: Dec. 04, 2024
- Modified: Apr. 24, 2025
-
6.5
MEDIUMCVE-2024-37547
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.4.0.... Read more
- Published: Jul. 06, 2024
- Modified: Apr. 24, 2025
-
7.8
HIGHCVE-2023-2603
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.... Read more
- Published: Jun. 06, 2023
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-0864
Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable unti... Read more
Affected Products : laragon- Published: Feb. 29, 2024
- Modified: Apr. 24, 2025
-
7.7
HIGHCVE-2024-45204
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting syste... Read more
Affected Products : veeam_backup_\&_replication- Published: Dec. 04, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54927
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54928
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2024-41446
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.... Read more
Affected Products : opencms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-42699
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field... Read more
Affected Products : opencms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-28121
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.... Read more
Affected Products : online_exam_mastering_system- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-29287
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : mcms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-24291
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.... Read more
Affected Products : yzmcms- Published: Feb. 06, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-24026
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.... Read more
Affected Products : novel-plus- Published: Feb. 08, 2024
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2023-6294
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.... Read more
Affected Products : popup_builder- Published: Feb. 12, 2024
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2023-50386
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from ... Read more
Affected Products : solr- Published: Feb. 09, 2024
- Modified: Apr. 24, 2025
-
6.7
MEDIUMCVE-2023-32835
In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08... Read more
- Published: Nov. 06, 2023
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2022-46411
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.... Read more
- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2022-46410
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.... Read more
Affected Products : netbackup_flex_scale_appliance- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-46405
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontro... Read more
Affected Products : mastodon- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
6.1
MEDIUMCVE-2022-46391
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.... Read more
- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025