Latest CVE Feed
-
9.8
CRITICALCVE-2024-6163
Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data... Read more
- Published: Jul. 08, 2024
- Modified: Aug. 27, 2025
-
6.5
MEDIUMCVE-2024-56430
OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.... Read more
Affected Products :- Published: Dec. 25, 2024
- Modified: Aug. 27, 2025
-
7.1
HIGHCVE-2024-56056
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through 1.4.3.... Read more
Affected Products : simplecharm- Published: Jan. 07, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-55551
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can fur... Read more
Affected Products : jdbc_driver- Published: Mar. 19, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2024-54175
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper check for unusual or exceptional conditions.... Read more
Affected Products : mq- Published: Feb. 28, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2024-53800
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.... Read more
Affected Products : rezgo_online_booking- Published: Jan. 07, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Path Traversal
-
8.4
HIGHCVE-2024-52531
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application ma... Read more
Affected Products : libsoup- Published: Nov. 11, 2024
- Modified: Aug. 27, 2025
-
8.1
HIGHCVE-2024-52323
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.... Read more
Affected Products : manageengine_analytics_plus- Published: Nov. 27, 2024
- Modified: Aug. 27, 2025
-
7.1
HIGHCVE-2024-51646
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saoshyant Saoshyant Element allows Reflected XSS.This issue affects Saoshyant Element: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Aug. 27, 2025
-
6.5
MEDIUMCVE-2024-50443
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.12.... Read more
Affected Products : postx- Published: Oct. 28, 2024
- Modified: Aug. 27, 2025
-
8.8
HIGHCVE-2024-50408
Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.... Read more
Affected Products : namaste\!_lms- Published: Oct. 28, 2024
- Modified: Aug. 27, 2025
-
6.9
MEDIUMCVE-2024-50313
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.7 only if the basic authentication mechanism is used by... Read more
Affected Products : mendix- Published: Nov. 12, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-4349
A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to u... Read more
Affected Products : pisay_online_e-learning_system- Published: Apr. 30, 2024
- Modified: Aug. 27, 2025
-
8.1
HIGHCVE-2024-4308
SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/... Read more
Affected Products : hubbank- Published: Apr. 29, 2024
- Modified: Aug. 27, 2025
-
9.8
CRITICALCVE-2024-48956
Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Aug. 27, 2025
-
7.2
HIGHCVE-2024-48889
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and Fo... Read more
- Published: Dec. 18, 2024
- Modified: Aug. 27, 2025
-
7.0
HIGHCVE-2024-47975
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Aug. 27, 2025
-
6.4
MEDIUMCVE-2024-45965
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.... Read more
Affected Products : contao- Published: Oct. 02, 2024
- Modified: Aug. 27, 2025
-
5.5
MEDIUMCVE-2024-45673
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be... Read more
- Published: Feb. 21, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2024-43176
IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.... Read more
- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authorization