Latest CVE Feed
-
9.9
CRITICALCVE-2024-55877
XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. Thi... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-55876
XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki withou... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-55875
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-55663
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2024-54811
A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.... Read more
- Published: Dec. 12, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-49147
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.... Read more
- Published: Dec. 12, 2024
- Modified: Jan. 10, 2025
-
6.5
MEDIUMCVE-2024-49071
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.... Read more
Affected Products : defender_for_endpoint- Published: Dec. 12, 2024
- Modified: Jan. 10, 2025
-
9.9
CRITICALCVE-2024-55662
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on th... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-54810
A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.... Read more
Affected Products : pre-school_enrollment_system- Published: Dec. 12, 2024
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2024-47238
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.... Read more
- Published: Dec. 12, 2024
- Modified: Feb. 04, 2025
-
6.3
MEDIUMCVE-2024-31670
rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.... Read more
Affected Products : rizin- Published: Dec. 12, 2024
- Modified: Jul. 02, 2025
-
9.8
CRITICALCVE-2024-55099
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.... Read more
Affected Products : online_nurse_hiring_system- Published: Dec. 12, 2024
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2024-52901
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.... Read more
Affected Products : infosphere_information_server- Published: Dec. 12, 2024
- Modified: Jan. 07, 2025
-
7.1
HIGHCVE-2024-55633
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgr... Read more
Affected Products : superset- Published: Dec. 12, 2024
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2024-54842
A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.... Read more
Affected Products : online_nurse_hiring_system- Published: Dec. 12, 2024
- Modified: Apr. 03, 2025
-
9.2
CRITICALCVE-2024-21575
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files ... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.4
MEDIUMCVE-2024-50584
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection at... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
8.4
HIGHCVE-2024-28146
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.9
MEDIUMCVE-2024-28145
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be perfo... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.5
MEDIUMCVE-2024-28144
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024