Latest CVE Feed
-
4.3
MEDIUMCVE-2024-6324
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.... Read more
Affected Products : gitlab- Published: Jan. 09, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2024-12736
The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : bu_section_editing- Published: Jan. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12731
The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : infeed- Published: Jan. 09, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12717
The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more
Affected Products : infeed- Published: Jan. 09, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12715
The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : asgard_security_scanner- Published: Jan. 09, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12714
The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : backlink_monitoring_manager- Published: Jan. 09, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2024-10815
The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers... Read more
Affected Products : postlists- Published: Jan. 09, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-0333
A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remot... Read more
Affected Products : cy-fast- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-0331
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation ... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-0328
A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipula... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-0306
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Cryptography
-
5.6
MEDIUMCVE-2024-56827
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.... Read more
- Published: Jan. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2024-56826
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.... Read more
- Published: Jan. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2024-13213
A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The expl... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-13212
A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestr... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-13211
A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access contr... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-13210
A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The ma... Read more
Affected Products : bookstore- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-13209
A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Managem... Read more
Affected Products : redaxo- Published: Jan. 09, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2024-13206
A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch ... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-13205
A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/create_product.php of the component Create Product Page. The manipulation of the argu... Read more
Affected Products : e-commerce-php- Published: Jan. 09, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting