Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-9852

    Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a spe... Read more

    Affected Products : genesis64 mc_works64
    • Published: Nov. 28, 2024
    • Modified: Dec. 06, 2024
  • 7.0

    HIGH
    CVE-2024-8300

    Dead Code vulnerability in ICONICS GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 and Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious cod... Read more

    Affected Products : genesis64
    • Published: Nov. 28, 2024
    • Modified: Dec. 06, 2024
  • 7.8

    HIGH
    CVE-2024-8299

    Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a spe... Read more

    Affected Products : genesis64 mc_works64
    • Published: Nov. 28, 2024
    • Modified: Dec. 06, 2024
  • 5.4

    MEDIUM
    CVE-2024-11971

    A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argum... Read more

    Affected Products : jpress
    • Published: Nov. 28, 2024
    • Modified: Dec. 03, 2024
  • 9.8

    CRITICAL
    CVE-2024-11970

    A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The manipulation of the argument mai leads to sql injection. It is possible to launch th... Read more

    Affected Products : concert_ticket_ordering_system
    • Published: Nov. 28, 2024
    • Modified: Dec. 02, 2024
  • 7.5

    HIGH
    CVE-2024-11968

    A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file pagamento.php. The manipulation of the argument notaFiscal leads to sql injection. The ... Read more

    Affected Products : farmacia farmacia farmacia
    • Published: Nov. 28, 2024
    • Modified: Dec. 03, 2024
  • 9.8

    CRITICAL
    CVE-2024-11967

    A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possib... Read more

    Affected Products : complaint_management_system
    • Published: Nov. 28, 2024
    • Modified: Dec. 03, 2024
  • 9.8

    CRITICAL
    CVE-2024-11966

    A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may b... Read more

    Affected Products : complaint_management_system
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-52338

    Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (... Read more

    Affected Products : arrow
    • Published: Nov. 28, 2024
    • Modified: Jul. 15, 2025
  • 9.8

    CRITICAL
    CVE-2024-11965

    A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The manipulation of the argument email leads to sql injection. The attac... Read more

    Affected Products : complaint_management_system
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-11964

    A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The manipulation of the argument emailid leads to sql injection. It is possible to initia... Read more

    Affected Products : complaint_management_system
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 8.8

    HIGH
    CVE-2024-11969

    The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code ... Read more

    Affected Products :
    • Published: Nov. 28, 2024
    • Modified: Nov. 28, 2024
  • 8.8

    HIGH
    CVE-2024-11963

    A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. ... Read more

    Affected Products : responsive_hotel_site
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-11962

    A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack ca... Read more

    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 7.5

    HIGH
    CVE-2024-11961

    A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the file src/main/java/com/zzjee/wm/controller/WmOmNoticeHController.java. The manipulation of t... Read more

    Affected Products : jeewms
    • Published: Nov. 28, 2024
    • Modified: Dec. 11, 2024
  • 9.0

    HIGH
    CVE-2024-11960

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. The attack ... Read more

    Affected Products : dir-605l_firmware dir-605l
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 9.0

    HIGH
    CVE-2024-11959

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possibl... Read more

    Affected Products : dir-605l_firmware dir-605l
    • Published: Nov. 28, 2024
    • Modified: Dec. 04, 2024
  • 7.8

    HIGH
    CVE-2023-52922

    In the Linux kernel, the following vulnerability has been resolved: can: bcm: Fix UAF in bcm_proc_show() BUG: KASAN: slab-use-after-free in bcm_proc_show+0x969/0xa80 Read of size 8 at addr ffff888155846230 by task cat/7862 CPU: 1 PID: 7862 Comm: cat No... Read more

    Affected Products : linux_kernel
    • Published: Nov. 28, 2024
    • Modified: Jun. 13, 2025
  • 6.5

    MEDIUM
    CVE-2024-7747

    The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible ... Read more

    Affected Products : terawallet
    • Published: Nov. 28, 2024
    • Modified: Jul. 15, 2025
  • 6.5

    MEDIUM
    CVE-2024-53731

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a through 1.0.3.... Read more

    Affected Products :
    • Published: Nov. 28, 2024
    • Modified: Nov. 28, 2024
Showing 20 of 291531 Results