Latest CVE Feed
-
6.8
MEDIUMCVE-2024-12086
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums... Read more
Affected Products : enterprise_linux openshift_container_platform rsync suse_linux linux nixos arch_linux smartos almalinux- Published: Jan. 14, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
8.0
HIGHCVE-2024-54887
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the r... Read more
- Published: Jan. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.6
CRITICALCVE-2024-55224
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.... Read more
Affected Products : vaultwarden- Published: Jan. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-55225
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.... Read more
Affected Products : vaultwarden- Published: Jan. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2024-37776
A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.... Read more
Affected Products : dctrack- Published: Dec. 16, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2024-37775
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.... Read more
Affected Products : dctrack- Published: Dec. 16, 2024
- Modified: Jun. 20, 2025
-
8.0
HIGHCVE-2024-37774
A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.... Read more
Affected Products : dctrack- Published: Dec. 16, 2024
- Modified: Jun. 20, 2025
-
7.8
HIGHCVE-2024-23347
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.... Read more
Affected Products : meta_spark_studio- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-22714
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.... Read more
Affected Products : stupid_simple_cms- Published: Jan. 17, 2024
- Modified: Jun. 20, 2025
-
7.2
HIGHCVE-2024-22627
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.... Read more
Affected Products : supplier_management_system- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2024-22362
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.... Read more
Affected Products : drupal- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2024-20985
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mu... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.9
MEDIUMCVE-2024-20983
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to ... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.9
MEDIUMCVE-2024-20981
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via m... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.9
MEDIUMCVE-2024-20965
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.5
MEDIUMCVE-2024-20961
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2024-20944
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
Affected Products : isupport- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-20942
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are affected are 11.5, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with ne... Read more
Affected Products : complex_maintenance\,_repair\,_and_overhaul complex_maintenance_repair_and_overhaul- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-20940
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
Affected Products : knowledge_management- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-20934
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network ac... Read more
Affected Products : installed_base- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025