Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-47540

    GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the program calls gst... Read more

    Affected Products : gstreamer
    • Published: Dec. 12, 2024
    • Modified: Dec. 18, 2024
  • 9.8

    CRITICAL
    CVE-2024-47539

    GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memo... Read more

    Affected Products : gstreamer
    • Published: Dec. 12, 2024
    • Modified: Dec. 18, 2024
  • 9.8

    CRITICAL
    CVE-2024-47538

    GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64... Read more

    Affected Products : gstreamer
    • Published: Dec. 12, 2024
    • Modified: Dec. 19, 2024
  • 9.8

    CRITICAL
    CVE-2024-47537

    GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that s... Read more

    Affected Products : gstreamer
    • Published: Dec. 12, 2024
    • Modified: Dec. 19, 2024
  • 8.1

    HIGH
    CVE-2024-45404

    OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the t... Read more

    Affected Products : opencti
    • Published: Dec. 12, 2024
    • Modified: May. 17, 2025
  • 9.1

    CRITICAL
    CVE-2024-45337

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this functio... Read more

    Affected Products : ssh
    • Published: Dec. 12, 2024
    • Modified: Feb. 18, 2025
  • 7.8

    HIGH
    CVE-2024-43600

    Microsoft Office Elevation of Privilege Vulnerability... Read more

    Affected Products : office
    • Published: Dec. 12, 2024
    • Modified: Jan. 08, 2025
  • 7.3

    HIGH
    CVE-2024-43594

    Microsoft System Center Elevation of Privilege Vulnerability... Read more

    • Published: Dec. 12, 2024
    • Modified: Jan. 08, 2025
  • 9.9

    CRITICAL
    CVE-2024-42448

    From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.... Read more

    Affected Products : veeam_service_provider_console
    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 7.5

    HIGH
    CVE-2024-37401

    An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.... Read more

    Affected Products : connect_secure policy_secure
    • Published: Dec. 12, 2024
    • Modified: Jul. 02, 2025
  • 7.5

    HIGH
    CVE-2024-37377

    A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.... Read more

    Affected Products : connect_secure policy_secure
    • Published: Dec. 12, 2024
    • Modified: Jul. 02, 2025
  • 8.8

    HIGH
    CVE-2024-12489

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/term.php. The manipulation of the argument id leads to sql injection. It is possibl... Read more

    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 8.8

    HIGH
    CVE-2024-12488

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/subject_update.php. The manipulation of the argument id leads to sql... Read more

    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 8.8

    HIGH
    CVE-2024-12487

    A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/room_update.php. The manipulation of the argument id lead... Read more

    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 8.8

    HIGH
    CVE-2024-12486

    A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It i... Read more

    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 8.8

    HIGH
    CVE-2024-12485

    A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/department.php. The manipulation of the argument id leads to sql ... Read more

    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-12484

    A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated... Read more

    Affected Products : technical_discussion_forum
    • Published: Dec. 12, 2024
    • Modified: Dec. 12, 2024
  • 6.3

    MEDIUM
    CVE-2024-12483

    A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the atta... Read more

    Affected Products : ujcms
    • Published: Dec. 12, 2024
    • Modified: Dec. 13, 2024
  • 5.3

    MEDIUM
    CVE-2024-12482

    A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basic-common\src\main\java\tech\wetech\basic\util\BackupFileUtil.java of the com... Read more

    Affected Products : wetech-cms
    • Published: Dec. 12, 2024
    • Modified: Dec. 13, 2024
  • 8.8

    HIGH
    CVE-2024-12481

    A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\UserDao.java. The manipulation ... Read more

    Affected Products : wetech-cms
    • Published: Dec. 12, 2024
    • Modified: Dec. 13, 2024
Showing 20 of 292870 Results