Latest CVE Feed
-
3.3
LOWCVE-2024-56810
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
3.3
LOWCVE-2024-56811
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
8.0
HIGHCVE-2025-25928
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In this case, an attacker could elevate a low-privileged account to an admini... Read more
Affected Products : openmrs- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2024-56812
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2024-57046
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.... Read more
- Published: Feb. 18, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-52702
A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Name parameter.... Read more
Affected Products : mybb- Published: Nov. 20, 2024
- Modified: Jul. 07, 2025
-
7.5
HIGHCVE-2024-52726
CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information... Read more
Affected Products : crmeb- Published: Nov. 22, 2024
- Modified: Jul. 07, 2025
-
5.5
MEDIUMCVE-2024-5285
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack... Read more
Affected Products : wp_affiliate_platform- Published: Jul. 29, 2024
- Modified: Jul. 07, 2025
-
7.5
HIGHCVE-2024-52871
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.... Read more
Affected Products : flagsmith- Published: Nov. 17, 2024
- Modified: Jul. 07, 2025
-
7.5
HIGHCVE-2024-52872
In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.... Read more
Affected Products : flagsmith- Published: Nov. 17, 2024
- Modified: Jul. 07, 2025
-
5.1
MEDIUMCVE-2024-53384
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components... Read more
Affected Products : tsup- Published: Mar. 03, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-53387
A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.... Read more
Affected Products : umeditor- Published: Mar. 03, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-53388
A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element.... Read more
Affected Products : mavo- Published: Mar. 03, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2024-35287
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource wi... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2024-35286
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensi... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2024-35285
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
6.3
MEDIUMCVE-2024-53619
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.... Read more
Affected Products : spip- Published: Nov. 26, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2024-35314
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sani... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
5.6
MEDIUMCVE-2024-35315
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. ... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
8.2
HIGHCVE-2024-47912
A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A suc... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025