Latest CVE Feed
-
8.4
HIGHCVE-2024-20104
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: M... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 24, 2025
-
6.7
MEDIUMCVE-2024-20106
In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08960505; Issue ID: MSV... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 24, 2025
-
6.2
MEDIUMCVE-2024-20107
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID:... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 24, 2025
-
6.5
MEDIUMCVE-2023-51327
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generat... Read more
Affected Products : cleaning_business_software- Published: Feb. 20, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-51326
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generat... Read more
Affected Products : cleaning_business_software- Published: Feb. 20, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2023-51315
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters.... Read more
Affected Products : restaurant_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2023-51314
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large ... Read more
Affected Products : restaurant_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2023-51301
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large am... Read more
Affected Products : hotel_booking_system- Published: Feb. 19, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2023-44753
A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-44752
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.... Read more
Affected Products : student_study_center_desk_management_system- Published: Apr. 22, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2023-44040
In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.... Read more
Affected Products : veridiumad- Published: Apr. 03, 2024
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2023-36643
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.... Read more
Affected Products : tradepro- Published: Apr. 04, 2024
- Modified: Apr. 24, 2025
-
9.3
CRITICALCVE-2024-7263
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitig... Read more
- Published: Aug. 15, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-20249
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is... Read more
Affected Products : telepresence_management_suite- Published: Apr. 24, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-36645
SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.... Read more
Affected Products : tradepro- Published: Apr. 04, 2024
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2023-36644
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.... Read more
Affected Products : tradepro- Published: Apr. 04, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-26686
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2023-26687
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-26688
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-26689
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025