Latest CVE Feed
-
6.5
MEDIUMCVE-2025-0195
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads... Read more
Affected Products : point_of_sales_and_inventory_management_system- Published: Jan. 03, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-56412
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker c... Read more
- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56411
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed without san... Read more
- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56410
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom propertie... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-36613
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.... Read more
Affected Products : ffmpeg- Published: Jan. 03, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-35365
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.... Read more
Affected Products : ffmpeg- Published: Jan. 03, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-21610
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javasc... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-21609
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a ... Read more
Affected Products : siyuan- Published: Jan. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-56514
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or a... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2024-56513
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive p... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Authorization
-
8.3
HIGHCVE-2024-56409
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsh... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56366
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspread... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56365
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/php... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56408
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` file, which leads to the pos... Read more
- Published: Jan. 03, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-56324
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: XML External Entity
-
7.2
HIGHCVE-2024-56322
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which ... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: XML External Entity
-
3.8
LOWCVE-2024-56321
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
-
9.4
CRITICALCVE-2024-56320
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authe... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-55507
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.... Read more
Affected Products : complaint_management_system- Published: Jan. 03, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-5591
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
- Published: Jan. 03, 2025
- Modified: Mar. 21, 2025