Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2024-12360

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The... Read more

    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 5.4

    MEDIUM
    CVE-2024-12359

    A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The a... Read more

    Affected Products : admin_dashboard
    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 8.8

    HIGH
    CVE-2024-12358

    A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the ... Read more

    Affected Products : datax-web
    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 6.9

    MEDIUM
    CVE-2024-12357

    A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to file inclusion. ... Read more

    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 5.9

    MEDIUM
    CVE-2024-53285

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read o... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53284

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges ... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53283

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges t... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53282

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileg... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53281

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files contain... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53280

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator priv... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.9

    MEDIUM
    CVE-2024-53279

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read ... Read more

    Affected Products : router_manager router_manager
    • Published: Dec. 09, 2024
    • Modified: Aug. 04, 2025
  • 5.7

    MEDIUM
    CVE-2024-55582

    Oxide before 6 has unencrypted Control Plane datastores.... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 11, 2024
  • 7.5

    HIGH
    CVE-2024-55580

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality ri... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 8.8

    HIGH
    CVE-2024-55579

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 4.3

    MEDIUM
    CVE-2024-55578

    Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.... Read more

    Affected Products : zammad
    • Published: Dec. 09, 2024
    • Modified: Apr. 15, 2025
  • 6.6

    MEDIUM
    CVE-2024-55566

    ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 17, 2024
  • 4.3

    MEDIUM
    CVE-2024-55565

    nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.... Read more

    Affected Products : nanoid
    • Published: Dec. 09, 2024
    • Modified: Dec. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-55564

    The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.... Read more

    Affected Products :
    • Published: Dec. 09, 2024
    • Modified: Dec. 09, 2024
  • 7.8

    HIGH
    CVE-2024-12355

    A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input valid... Read more

    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
  • 7.8

    HIGH
    CVE-2024-12354

    A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible... Read more

    • Published: Dec. 09, 2024
    • Modified: Dec. 10, 2024
Showing 20 of 291963 Results