Latest CVE Feed
-
7.8
HIGHCVE-2024-49538
Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Dec. 10, 2024
- Modified: Jul. 07, 2025
-
7.8
HIGHCVE-2024-49537
After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a ... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-49513
PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 19, 2024
-
7.8
HIGHCVE-2024-45156
Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-45155
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
6.1
MEDIUMCVE-2024-53481
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.... Read more
Affected Products : beauty_parlour_management_system- Published: Dec. 10, 2024
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2024-53480
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.... Read more
Affected Products : beauty_parlour_management_system- Published: Dec. 10, 2024
- Modified: Apr. 07, 2025
-
7.5
HIGHCVE-2024-51165
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Dec. 10, 2024
- Modified: Jun. 24, 2025
-
5.5
MEDIUMCVE-2024-49554
Media Encoder versions 25.0, 24.6.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of s... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-49553
Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-49552
Media Encoder versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
Affected Products : media_encoder- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-49551
Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 18, 2024
-
6.3
MEDIUMCVE-2024-49535
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input ... Read more
- Published: Dec. 10, 2024
- Modified: Jan. 23, 2025
-
5.5
MEDIUMCVE-2024-49534
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t... Read more
- Published: Dec. 10, 2024
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2024-49533
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t... Read more
- Published: Dec. 10, 2024
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2024-49532
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability t... Read more
- Published: Dec. 10, 2024
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2024-49531
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnera... Read more
- Published: Dec. 10, 2024
- Modified: Jan. 21, 2025
-
7.8
HIGHCVE-2024-49530
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this ... Read more
- Published: Dec. 10, 2024
- Modified: Jan. 21, 2025
-
8.0
HIGHCVE-2024-46341
TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.... Read more
- Published: Dec. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-46340
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.... Read more
- Published: Dec. 10, 2024
- Modified: Jun. 20, 2025