Latest CVE Feed
-
9.8
CRITICALCVE-2024-13004
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/category.php. The manipulation of the argument state leads to sql injection. It is possible to initiate th... Read more
Affected Products : complaint_management_system- Published: Dec. 29, 2024
- Modified: Dec. 29, 2024
-
7.5
HIGHCVE-2018-25107
The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits.... Read more
Affected Products :- Published: Dec. 29, 2024
- Modified: Dec. 31, 2024
-
6.3
MEDIUMCVE-2024-12238
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does ... Read more
Affected Products : ninja_forms- Published: Dec. 29, 2024
- Modified: Apr. 18, 2025
-
9.8
CRITICALCVE-2024-13003
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /update_ed.php. The manipulation of the argument e_id leads to sql injection. T... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 29, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-13002
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /order_process.php. The manipulation of the argument fnm leads to sql inje... Read more
Affected Products : bookstore_management_system- Published: Dec. 29, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-13001
A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack rem... Read more
Affected Products : small_crm- Published: Dec. 29, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-13000
A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/quote-details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remo... Read more
Affected Products : small_crm- Published: Dec. 29, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2024-12999
A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remote... Read more
Affected Products : small_crm- Published: Dec. 29, 2024
- Modified: Feb. 18, 2025
-
6.9
MEDIUMCVE-2024-12998
A vulnerability, which was classified as problematic, was found in code-projects Online Car Rental System 1.0. This affects an unknown part of the file /index.php of the component GET Parameter Handler. The manipulation leads to cross site scripting. It i... Read more
Affected Products : online_car_rental_system- Published: Dec. 28, 2024
- Modified: Mar. 03, 2025
-
5.4
MEDIUMCVE-2024-56512
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include bindin... Read more
Affected Products : nifi- Published: Dec. 28, 2024
- Modified: Feb. 11, 2025
-
5.3
MEDIUMCVE-2024-12995
A vulnerability classified as problematic has been found in ruifang-tech Rebuild 3.8.6. This affects an unknown part of the file /project/050-9000000000000001/tasks of the component Project Tasks Section. The manipulation of the argument description leads... Read more
Affected Products : rebuild- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
6.5
MEDIUMCVE-2024-12994
A vulnerability was found in running-elephant Datart 1.0.0-rc3. It has been rated as critical. Affected by this issue is the function extractModel of the file /import of the component File Upload. The manipulation of the argument file leads to deserializa... Read more
Affected Products :- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
7.8
HIGHCVE-2024-56708
In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. In igen6_probe(), igen6_pvt will be allocated with kzalloc() 2. In ige... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Jan. 08, 2025
-
0.0
NACVE-2024-56707
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c Add error pointer checks after calling otx2_mbox_get_rsp().... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
0.0
NACVE-2024-56706
In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Fix and protect memory allocation of SDBs with mutex Reservation of the PMU hardware is done at first event creation and is protected by a pair of mutex_lock() and mutex_u... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
0.0
NACVE-2024-56705
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Add check for rgby_data memory allocation failure In ia_css_3a_statistics_allocate(), there is no check on the allocation result of the rgby_data memory. If rgby_data is... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Apr. 18, 2025
-
7.8
HIGHCVE-2024-56704
In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device ID during IRQ release. [Dominique: remove confusing variable reset to 0]... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Jan. 13, 2025
-
5.5
MEDIUMCVE-2024-56703
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under high next hop churn Soft lockups have been observed on a cluster of Linux-based edge routers located in a highly dynamic environment. Us... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Feb. 02, 2025
-
5.5
MEDIUMCVE-2024-56702
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark raw_tp arguments with PTR_MAYBE_NULL Arguments to a raw tracepoint are tagged as trusted, which carries the semantics that the pointer will be non-NULL. However, in certain c... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Feb. 03, 2025
-
0.0
NACVE-2024-56701
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore The dtl_access_lock needs to be a rw_sempahore, a sleeping lock, because the code calls kmalloc() while holding it, which can s... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024