Latest CVE Feed
-
9.8
CRITICALCVE-2023-22701
Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.... Read more
Affected Products : ebook_store- Published: Dec. 09, 2024
- Modified: Feb. 27, 2025
-
4.3
MEDIUMCVE-2024-46901
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All ... Read more
- Published: Dec. 09, 2024
- Modified: Jul. 15, 2025
-
4.3
MEDIUMCVE-2024-12307
A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability exists due to missing access control checks in t... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2024-12306
Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in l... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2024-12305
An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
6.1
MEDIUMCVE-2024-9651
The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : contact_form- Published: Dec. 09, 2024
- Modified: May. 06, 2025
-
8.8
HIGHCVE-2024-12360
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2024-12359
A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The a... Read more
Affected Products : admin_dashboard- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
8.8
HIGHCVE-2024-12358
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the ... Read more
Affected Products : datax-web- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
6.9
MEDIUMCVE-2024-12357
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to file inclusion. ... Read more
Affected Products : best_house_rental_management_system- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
5.9
MEDIUMCVE-2024-53285
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read o... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53284
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges ... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53283
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges t... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53282
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileg... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53281
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files contain... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53280
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator priv... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2024-53279
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read ... Read more
- Published: Dec. 09, 2024
- Modified: Aug. 04, 2025
-
5.7
MEDIUMCVE-2024-55582
Oxide before 6 has unencrypted Control Plane datastores.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
7.5
HIGHCVE-2024-55580
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality ri... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
8.8
HIGHCVE-2024-55579
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024