Latest CVE Feed
-
9.1
CRITICALCVE-2024-51164
Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2025-1854
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. The manipulation of the argument name leads to sql injection. It is possible ... Read more
Affected Products : gym_management_system- Published: Mar. 03, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2021-1470
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQ... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-13209
A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Managem... Read more
Affected Products : redaxo- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-3129
A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the file /endpoint/add-image.php. The manipulation of the argument image_name leads to unrestricted upload. It... Read more
Affected Products : image_accordion_gallery_app- Published: Apr. 01, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.... Read more
Affected Products : nagios_xi- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-6517
A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of the compone... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2024-31470
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point managem... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-31469
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP po... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-31468
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP po... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-31467
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successf... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-31466
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successf... Read more
- Published: May. 14, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-55226
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.... Read more
Affected Products : vaultwarden- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
8.4
HIGHCVE-2024-47796
An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : dcmtk- Published: Jan. 13, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-52333
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : dcmtk- Published: Jan. 13, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-51379
Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of ma... Read more
Affected Products : jatos- Published: Nov. 05, 2024
- Modified: Jun. 24, 2025
-
8.4
HIGHCVE-2024-51380
Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin u... Read more
Affected Products : jatos- Published: Nov. 05, 2024
- Modified: Jun. 24, 2025
-
8.4
HIGHCVE-2024-51381
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and ... Read more
Affected Products : jatos- Published: Nov. 05, 2024
- Modified: Jun. 24, 2025
-
8.4
HIGHCVE-2024-51382
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compro... Read more
Affected Products : jatos- Published: Nov. 05, 2024
- Modified: Jun. 24, 2025
-
6.1
MEDIUMCVE-2023-1932
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid h... Read more
- Published: Nov. 07, 2024
- Modified: Jun. 24, 2025