Latest CVE Feed
-
7.5
HIGHCVE-2024-49353
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.... Read more
Affected Products : watson_assistant_for_ibm_cloud_pak_for_data- Published: Nov. 26, 2024
- Modified: Aug. 15, 2025
-
5.5
MEDIUMCVE-2024-49351
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.... Read more
- Published: Nov. 26, 2024
- Modified: Aug. 08, 2025
-
6.1
MEDIUMCVE-2024-11418
The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shipping_method_filter' parameter in all versions up to, and including, 1.21 due to insufficient input sanitization and output escap... Read more
Affected Products : additional_order_filters_for_woocommerce- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.1
MEDIUMCVE-2024-11342
The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing or incorrect nonce validation in the skt-nurc-admin.php file. This makes it possible for unauthenticate... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
7.6
HIGHCVE-2024-49597
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection m... Read more
Affected Products : wyse_management_suite- Published: Nov. 26, 2024
- Modified: Feb. 04, 2025
-
6.5
MEDIUMCVE-2024-49596
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion... Read more
Affected Products : wyse_management_suite- Published: Nov. 26, 2024
- Modified: Feb. 04, 2025
-
7.6
HIGHCVE-2024-49595
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.... Read more
Affected Products : wyse_management_suite- Published: Nov. 26, 2024
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2024-11678
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. The manipulation of the argument pat_fname/pat_ailme... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2024-11677
A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php of the component Add Vendor Details Page. The manipulation of th... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
8.8
HIGHCVE-2024-10729
The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_calendar_data' function in versions up to, and including, 6.9.0. This makes it p... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
8.8
HIGHCVE-2024-52899
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.... Read more
Affected Products : data_virtualization_manager_for_z\/os- Published: Nov. 26, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-11676
A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /backend/admin/his_admin_add_lab_equipment.php of the component Add Laboratory Equipment ... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2024-11675
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Det... Read more
- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
8.1
HIGHCVE-2024-53843
@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend clients to interface with keycloak. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the authentication flow of the... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
8.8
HIGHCVE-2024-11674
A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The manipulation of the argument doc_dpic leads to unrestricted ... Read more
Affected Products : hospital_management_system- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
6.9
MEDIUMCVE-2024-11673
A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. ... Read more
Affected Products : bookstore_management_system- Published: Nov. 25, 2024
- Modified: Dec. 04, 2024
-
6.3
MEDIUMCVE-2024-53597
masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.... Read more
Affected Products :- Published: Nov. 25, 2024
- Modified: Nov. 27, 2024
-
8.0
HIGHCVE-2024-53554
A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.... Read more
Affected Products :- Published: Nov. 25, 2024
- Modified: Nov. 26, 2024
-
5.5
MEDIUMCVE-2024-53101
In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in a trace point even though ATTR_MODE, ATTR_UID and ATTR_... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2024
- Modified: Dec. 19, 2024
-
4.7
MEDIUMCVE-2024-53100
In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and destroy Commit 76d54bf20cdc ("nvme-tcp: don't access released socket during error recovery") added a mutex_lock() call for the queue->q... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2024
- Modified: Dec. 24, 2024