Latest CVE Feed
-
8.4
HIGHCVE-2024-54149
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandbox pl... Read more
Affected Products : winter- Published: Dec. 09, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-46455
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
4.2
MEDIUMCVE-2024-12369
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization c... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Apr. 17, 2025
-
9.1
CRITICALCVE-2024-53441
An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 12, 2024
-
7.5
HIGHCVE-2024-54938
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-54934
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-54932
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-54931
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54928
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2024-54927
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-54925
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54924
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54923
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54921
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parame... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2024-54918
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Apr. 14, 2025
-
6.8
MEDIUMCVE-2024-54147
Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi,... Read more
Affected Products : altair- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.1
MEDIUMCVE-2024-53847
The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary Java... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2024-52599
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability t... Read more
Affected Products : tuleap- Published: Dec. 09, 2024
- Modified: Aug. 22, 2025
-
7.8
HIGHCVE-2024-52586
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker... Read more
Affected Products : elabftw- Published: Dec. 09, 2024
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2024-48956
Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Aug. 27, 2025