Latest CVE Feed
-
7.5
HIGHCVE-2024-13200
A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. ... Read more
Affected Products : springboot-blog- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
3.6
LOWCVE-2024-37372
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.... Read more
Affected Products : node.js- Published: Jan. 09, 2025
- Modified: May. 02, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2024-27980
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.... Read more
Affected Products : node.js- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-13199
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scr... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2024-13198
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The c... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
-
5.5
MEDIUMCVE-2023-38037
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the c... Read more
Affected Products : activesupport- Published: Jan. 09, 2025
- Modified: Feb. 15, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Lo... Read more
Affected Products : actionpack- Published: Jan. 09, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2023-28120
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.... Read more
Affected Products : activesupport- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2023-27539
There is a denial of service vulnerability in the header parsing component of Rack.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2023-27531
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
6.3
MEDIUMCVE-2023-23913
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the ... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13197
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads t... Read more
Affected Products : bookstore- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13196
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore/web/controller/BookInfoController.java. The manipulatio... Read more
Affected Products : bookstore- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-13195
A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side... Read more
Affected Products : bookstore- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
8.8
HIGHCVE-2024-13194
A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched... Read more
Affected Products : sucms- Published: Jan. 09, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
7.0
HIGHCVE-2025-0283
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.... Read more
- Published: Jan. 08, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2025-0282
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execu... Read more
- Actively Exploited
- Published: Jan. 08, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-13193
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection... Read more
Affected Products : semcms- Published: Jan. 08, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-13192
A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is pos... Read more
Affected Products : myblog- Published: Jan. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-13191
A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to... Read more
Affected Products : myblog- Published: Jan. 08, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication