Latest CVE Feed
-
7.5
HIGHCVE-2024-40582
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.... Read more
Affected Products : curovms- Published: Dec. 09, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2022-38947
SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.... Read more
Affected Products : flipkart-clone-php- Published: Dec. 09, 2024
- Modified: May. 17, 2025
-
9.8
CRITICALCVE-2024-54920
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id par... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2024-54919
A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
6.5
MEDIUMCVE-2024-49603
Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.... Read more
Affected Products : powerscale_onefs- Published: Dec. 09, 2024
- Modified: Jan. 09, 2025
-
6.5
MEDIUMCVE-2024-49602
Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : powerscale_onefs- Published: Dec. 09, 2024
- Modified: Jan. 09, 2025
-
7.8
HIGHCVE-2024-49600
Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges.... Read more
Affected Products : power_manager- Published: Dec. 09, 2024
- Modified: Feb. 04, 2025
-
6.5
MEDIUMCVE-2024-42426
Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : powerscale_onefs- Published: Dec. 09, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2024-38485
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.... Read more
Affected Products : elastic_cloud_storage- Published: Dec. 09, 2024
- Modified: Feb. 04, 2025
-
5.6
MEDIUMCVE-2024-11991
Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. Ho... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
8.8
HIGHCVE-2023-7298
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of th... Read more
Affected Products : fbx_software_development_kit- Published: Dec. 09, 2024
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2024-8259
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: thr... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 13, 2024
-
5.3
MEDIUMCVE-2024-54937
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2024-54936
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
7.2
HIGHCVE-2024-54929
KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Mar. 18, 2025
-
6.5
MEDIUMCVE-2024-54218
Missing Authorization vulnerability in Thehp AIO Contact.This issue affects AIO Contact: from n/a through 2.8.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
7.6
HIGHCVE-2024-53949
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgra... Read more
Affected Products : superset- Published: Dec. 09, 2024
- Modified: Feb. 12, 2025
-
5.3
MEDIUMCVE-2024-53948
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.... Read more
Affected Products : superset- Published: Dec. 09, 2024
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2024-53947
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. T... Read more
Affected Products : superset- Published: Dec. 09, 2024
- Modified: Jul. 15, 2025
-
6.5
MEDIUMCVE-2024-53814
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Analytify.This issue affects Analytify: from n/a through 5.4.3.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025