Latest CVE Feed
-
9.8
CRITICALCVE-2024-11967
A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possib... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2024-11966
A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may b... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (... Read more
Affected Products : arrow- Published: Nov. 28, 2024
- Modified: Jul. 15, 2025
-
9.8
CRITICALCVE-2024-11965
A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The manipulation of the argument email leads to sql injection. The attac... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-11964
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The manipulation of the argument emailid leads to sql injection. It is possible to initia... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
8.8
HIGHCVE-2024-11969
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code ... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
8.8
HIGHCVE-2024-11963
A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. ... Read more
Affected Products : responsive_hotel_site- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-11962
A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack ca... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
7.5
HIGHCVE-2024-11961
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the file src/main/java/com/zzjee/wm/controller/WmOmNoticeHController.java. The manipulation of t... Read more
Affected Products : jeewms- Published: Nov. 28, 2024
- Modified: Dec. 11, 2024
-
9.0
HIGHCVE-2024-11960
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. The attack ... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.0
HIGHCVE-2024-11959
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possibl... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
7.8
HIGHCVE-2023-52922
In the Linux kernel, the following vulnerability has been resolved: can: bcm: Fix UAF in bcm_proc_show() BUG: KASAN: slab-use-after-free in bcm_proc_show+0x969/0xa80 Read of size 8 at addr ffff888155846230 by task cat/7862 CPU: 1 PID: 7862 Comm: cat No... Read more
Affected Products : linux_kernel- Published: Nov. 28, 2024
- Modified: Jun. 13, 2025
-
6.5
MEDIUMCVE-2024-7747
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible ... Read more
Affected Products : terawallet- Published: Nov. 28, 2024
- Modified: Jul. 15, 2025
-
6.5
MEDIUMCVE-2024-53731
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a through 1.0.3.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.5
MEDIUMCVE-2024-8308
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.5
MEDIUMCVE-2024-53737
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.... Read more
Affected Products : wp_mailster- Published: Nov. 28, 2024
- Modified: Feb. 10, 2025
-
7.1
HIGHCVE-2024-53736
Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars allows Stored XSS.This issue affects Custom Shortcode Sidebars: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53734
Cross-Site Request Forgery (CSRF) vulnerability in Idealien Studios Idealien Category Enhancements allows Stored XSS.This issue affects Idealien Category Enhancements: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53733
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rohit Harsh Fence URL allows Stored XSS.This issue affects Fence URL: from n/a through 2.0.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53732
Cross-Site Request Forgery (CSRF) vulnerability in WP WOX Footer Flyout Widget allows Stored XSS.This issue affects Footer Flyout Widget: from n/a through 1.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024