Latest CVE Feed
-
6.1
MEDIUMCVE-2024-25715
Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.... Read more
Affected Products : glewlwyd_sso_server- Published: Feb. 11, 2024
- Modified: Jun. 16, 2025
-
6.1
MEDIUMCVE-2024-25712
http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-248... Read more
Affected Products : http-swagger- Published: Feb. 29, 2024
- Modified: Jun. 16, 2025
-
6.5
MEDIUMCVE-2024-25679
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed a... Read more
Affected Products : pquic- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2024-25677
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.... Read more
Affected Products : min- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
5.5
MEDIUMCVE-2024-25453
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.... Read more
Affected Products : bento4- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2024-25450
imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().... Read more
Affected Products : imlib2- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2024-25318
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.... Read more
Affected Products : hotel_management_system- Published: Feb. 09, 2024
- Modified: Jun. 16, 2025
-
6.1
MEDIUMCVE-2024-24034
Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.... Read more
Affected Products : s.i.l- Published: Feb. 08, 2024
- Modified: Jun. 16, 2025
-
7.8
HIGHCVE-2024-22749
GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577... Read more
Affected Products : gpac- Published: Jan. 25, 2024
- Modified: Jun. 16, 2025
-
7.8
HIGHCVE-2024-22562
swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.... Read more
Affected Products : swftools- Published: Jan. 19, 2024
- Modified: Jun. 16, 2025
-
7.5
HIGHCVE-2024-22050
Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs. ... Read more
Affected Products : iodine- Published: Jan. 04, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2024-21833
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 16, 2025
-
7.5
HIGHCVE-2024-21780
Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported.... Read more
- Published: Feb. 02, 2024
- Modified: Jun. 16, 2025
-
4.3
MEDIUMCVE-2024-0811
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)... Read more
- Published: Jan. 24, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51984
D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51968
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51960
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2023-51939
An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.... Read more
Affected Products : relic- Published: Feb. 01, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51928
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : yonbip- Published: Jan. 20, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51927
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.... Read more
Affected Products : yonbip- Published: Jan. 20, 2024
- Modified: Jun. 16, 2025