Latest CVE Feed
-
9.8
CRITICALCVE-2024-55461
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().... Read more
Affected Products : seacms- Published: Dec. 18, 2024
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2024-55239
A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.... Read more
Affected Products : i-educar- Published: Dec. 18, 2024
- Modified: Jul. 03, 2025
-
7.5
HIGHCVE-2024-53580
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Apr. 04, 2025
-
9.1
CRITICALCVE-2024-43106
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigge... Read more
Affected Products : excel- Published: Dec. 18, 2024
- Modified: Aug. 22, 2025
-
9.1
CRITICALCVE-2024-42220
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to ... Read more
Affected Products : outlook- Published: Dec. 18, 2024
- Modified: Aug. 22, 2025
-
9.8
CRITICALCVE-2024-42004
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2024-41165
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger ... Read more
Affected Products : word- Published: Dec. 18, 2024
- Modified: Aug. 22, 2025
-
7.1
HIGHCVE-2024-41159
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to tr... Read more
Affected Products : onenote- Published: Dec. 18, 2024
- Modified: Aug. 25, 2025
-
9.8
CRITICALCVE-2024-41145
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious appl... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
9.8
CRITICALCVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission ... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2024-39804
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program... Read more
Affected Products : powerpoint- Published: Dec. 18, 2024
- Modified: Aug. 25, 2025
-
4.6
MEDIUMCVE-2024-37649
Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 31, 2024
-
6.5
MEDIUMCVE-2022-40733
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-c... Read more
- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
7.5
HIGHCVE-2022-40732
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-c... Read more
- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-55505
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.... Read more
Affected Products : complaint_management_system- Published: Dec. 18, 2024
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2024-55232
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete... Read more
- Published: Dec. 18, 2024
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2024-55231
An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and en... Read more
- Published: Dec. 18, 2024
- Modified: Mar. 27, 2025
-
8.8
HIGHCVE-2024-12695
Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Dec. 18, 2024
- Modified: Feb. 11, 2025
-
8.8
HIGHCVE-2024-12694
Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Dec. 18, 2024
- Modified: Feb. 11, 2025
-
8.8
HIGHCVE-2024-12693
Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Dec. 18, 2024
- Modified: Mar. 13, 2025