Latest CVE Feed
-
6.5
MEDIUMCVE-2023-51317
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.... Read more
Affected Products : restaurant_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-44724
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.... Read more
Affected Products : autocms- Published: Sep. 09, 2024
- Modified: Apr. 22, 2025
-
7.2
HIGHCVE-2024-44725
AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.... Read more
Affected Products : autocms- Published: Sep. 09, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2023-51318
PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.... Read more
Affected Products : bus_reservation_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2023-51319
PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System O... Read more
Affected Products : bus_reservation_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-44838
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.... Read more
Affected Products : rapidcms- Published: Sep. 06, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-44839
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.... Read more
Affected Products : rapidcms- Published: Sep. 06, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-45771
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.... Read more
Affected Products : rapidcms- Published: Sep. 06, 2024
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-51320
PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in Sys... Read more
Affected Products : night_club_booking_software- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-41375
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php... Read more
Affected Products : icecoder- Published: Jul. 26, 2024
- Modified: Apr. 22, 2025
-
6.5
MEDIUMCVE-2023-51321
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of genera... Read more
Affected Products : night_club_booking_software- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2024-41374
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php... Read more
Affected Products : icecoder- Published: Jul. 26, 2024
- Modified: Apr. 22, 2025
-
6.3
MEDIUMCVE-2024-41373
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.... Read more
Affected Products : icecoder- Published: Jul. 26, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20130
In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09193374; Issue ID: M... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20131
In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20133
In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20134
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09154589; Issue ID: MSV... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20135
In soundtrigger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09142526; Issu... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.2
MEDIUMCVE-2024-20136
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID:... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
6.7
MEDIUMCVE-2024-20119
In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: ... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 22, 2025