Latest CVE Feed
-
8.8
HIGHCVE-2024-37840
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.... Read more
Affected Products : learning_management_system- Published: Jun. 17, 2024
- Modified: Jun. 10, 2025
-
7.3
HIGHCVE-2024-33300
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.... Read more
Affected Products : typora- Published: May. 01, 2024
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2024-34401
Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.... Read more
Affected Products : savsoft_quiz- Published: May. 03, 2024
- Modified: Jun. 10, 2025
-
8.8
HIGHCVE-2024-33921
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21. ... Read more
Affected Products : reviewx- Published: May. 03, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2024-33789
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.... Read more
- Published: May. 03, 2024
- Modified: Jun. 10, 2025
-
8.6
HIGHCVE-2024-27453
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).... Read more
Affected Products : extremexos- Published: May. 03, 2024
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2024-34462
Alinto SOGo through 5.10.0 allows XSS during attachment preview.... Read more
Affected Products : sogo- Published: May. 04, 2024
- Modified: Jun. 10, 2025
-
4.3
MEDIUMCVE-2024-34508
dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.... Read more
- Published: May. 05, 2024
- Modified: Jun. 10, 2025
-
4.0
MEDIUMCVE-2024-31580
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
Affected Products : pytorch- Published: Apr. 17, 2024
- Modified: Jun. 10, 2025
-
7.5
HIGHCVE-2024-35618
PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.... Read more
Affected Products : tidb- Published: May. 24, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2024-35373
Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.... Read more
Affected Products : mocodo_online- Published: May. 24, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2024-35374
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain ... Read more
Affected Products : mocodo_online- Published: May. 24, 2024
- Modified: Jun. 10, 2025
-
6.3
MEDIUMCVE-2024-34852
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name ... Read more
- Published: May. 28, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2024-34854
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`... Read more
- Published: May. 28, 2024
- Modified: Jun. 10, 2025
-
6.5
MEDIUMCVE-2023-36235
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.... Read more
Affected Products : qloapps- Published: Jan. 17, 2024
- Modified: Jun. 10, 2025
-
7.5
HIGHCVE-2023-30305
An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.... Read more
- Published: May. 28, 2024
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2024-28390
An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.... Read more
- Published: Mar. 14, 2024
- Modified: Jun. 10, 2025
-
7.5
HIGHCVE-2024-26529
An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.... Read more
Affected Products : libiec61850- Published: Mar. 13, 2024
- Modified: Jun. 10, 2025
-
7.5
HIGHCVE-2024-8474
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic... Read more
Affected Products : connect- Published: Jan. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-5594
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.... Read more
Affected Products : openvpn- Published: Jan. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Information Disclosure