Latest CVE Feed
-
9.8
CRITICALCVE-2024-54931
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54928
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54927
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-54925
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54924
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54923
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54921
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parame... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54918
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
6.8
MEDIUMCVE-2024-54147
Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi,... Read more
Affected Products : altair- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.1
MEDIUMCVE-2024-53847
The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary Java... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2024-52599
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability t... Read more
Affected Products : tuleap- Published: Dec. 09, 2024
- Modified: Aug. 22, 2025
-
7.8
HIGHCVE-2024-52586
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker... Read more
Affected Products : elabftw- Published: Dec. 09, 2024
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2024-48956
Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-46547
A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leak... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
1.8
LOWCVE-2024-12057
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the ... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2022-29974
AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in certain ASUS devices.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2024-54935
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2024-54933
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2024-54930
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2024-54922
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024