Latest CVE Feed
-
5.3
MEDIUMCVE-2025-21610
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javasc... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-21609
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a ... Read more
Affected Products : siyuan- Published: Jan. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-56514
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or a... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2024-56513
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive p... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Authorization
-
8.3
HIGHCVE-2024-56409
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsh... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56366
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspread... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56365
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/php... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56408
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` file, which leads to the pos... Read more
- Published: Jan. 03, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-56324
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: XML External Entity
-
7.2
HIGHCVE-2024-56322
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which ... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: XML External Entity
-
3.8
LOWCVE-2024-56321
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
-
9.4
CRITICALCVE-2024-56320
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authe... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-55507
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.... Read more
Affected Products : complaint_management_system- Published: Jan. 03, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-5591
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
- Published: Jan. 03, 2025
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2024-55078
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-48814
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function... Read more
Affected Products : silverpeas- Published: Jan. 03, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2024-41780
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.... Read more
- Published: Jan. 03, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-9140
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execu... Read more
Affected Products : tn-4900_firmware- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2024-9138
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-... Read more
- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-12132
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This ... Read more
Affected Products : wp_job_portal- Published: Jan. 03, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization