Latest CVE Feed
-
6.4
MEDIUMCVE-2024-3974
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products : buddypress- Published: May. 14, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-3729
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to mani... Read more
Affected Products : frontend_admin- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-3554
The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.6.0 due to insufficient... Read more
Affected Products : all_in_one_seo- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
5.4
MEDIUMCVE-2024-1809
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up t... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
8.6
HIGHCVE-2024-42552
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42553
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42554
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42555
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42556
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42557
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42558
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
6.1
MEDIUMCVE-2024-42560
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details ... Read more
Affected Products : blood_bank_and_donation_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42561
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42562
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.... Read more
Affected Products : pharmacy_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42563
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42569
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.... Read more
Affected Products : school_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42571
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
7.8
HIGHCVE-2024-22705
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandle... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2024
- Modified: Jun. 05, 2025
-
6.3
MEDIUMCVE-2024-22099
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2... Read more
Affected Products : linux_kernel- Published: Jan. 25, 2024
- Modified: Jun. 05, 2025
-
4.9
MEDIUMCVE-2023-34324
Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of a... Read more
- Published: Jan. 05, 2024
- Modified: Jun. 05, 2025