Latest CVE Feed
-
7.5
HIGHCVE-2024-48651
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.... Read more
Affected Products : proftpd- Published: Nov. 29, 2024
- Modified: Mar. 17, 2025
-
4.3
MEDIUMCVE-2024-45495
MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Dec. 04, 2024
-
4.8
MEDIUMCVE-2024-35451
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.... Read more
Affected Products : linkstack- Published: Nov. 29, 2024
- Modified: Jul. 03, 2025
-
8.8
HIGHCVE-2024-54124
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.... Read more
Affected Products : passwordstate- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
6.1
MEDIUMCVE-2024-54123
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
9.8
CRITICALCVE-2024-11979
DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading websh... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
7.5
HIGHCVE-2024-11978
DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
7.8
HIGHCVE-2024-9852
Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a spe... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 06, 2024
-
7.0
HIGHCVE-2024-8300
Dead Code vulnerability in ICONICS GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 and Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious cod... Read more
Affected Products : genesis64- Published: Nov. 28, 2024
- Modified: Dec. 06, 2024
-
7.8
HIGHCVE-2024-8299
Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a spe... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 06, 2024
-
5.4
MEDIUMCVE-2024-11971
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argum... Read more
Affected Products : jpress- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2024-11970
A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The manipulation of the argument mai leads to sql injection. It is possible to launch th... Read more
Affected Products : concert_ticket_ordering_system- Published: Nov. 28, 2024
- Modified: Dec. 02, 2024
-
7.5
HIGHCVE-2024-11968
A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file pagamento.php. The manipulation of the argument notaFiscal leads to sql injection. The ... Read more
- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2024-11967
A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possib... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2024-11966
A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may b... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (... Read more
Affected Products : arrow- Published: Nov. 28, 2024
- Modified: Jul. 15, 2025
-
9.8
CRITICALCVE-2024-11965
A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The manipulation of the argument email leads to sql injection. The attac... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-11964
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The manipulation of the argument emailid leads to sql injection. It is possible to initia... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024
-
8.8
HIGHCVE-2024-11969
The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code ... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
8.8
HIGHCVE-2024-11963
A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. ... Read more
Affected Products : responsive_hotel_site- Published: Nov. 28, 2024
- Modified: Dec. 04, 2024