Latest CVE Feed
-
7.5
HIGHCVE-2024-11241
A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file reset.php. The manipulation of the argument e leads to sql injection. The attack can b... Read more
Affected Products : job_recruitment- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
9.1
CRITICALCVE-2023-20154
A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges. This vulnerability is due to the improper handling of certain me... Read more
Affected Products : modeling_labs- Published: Nov. 15, 2024
- Modified: Aug. 05, 2025
-
8.6
HIGHCVE-2023-20125
A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting does not... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-11240
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. The manipulation of the argument db_login_role leads to ... Read more
Affected Products : ibwebadmin- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.5
MEDIUMCVE-2024-11239
A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=deleteFile of the component API Interface. The manipulation of the argument fo... Read more
Affected Products : landray_ekp- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
6.9
MEDIUMCVE-2024-11238
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath l... Read more
Affected Products : landray_ekp- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11237
A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to s... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
6.1
MEDIUMCVE-2024-1240
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, whi... Read more
Affected Products : pyload- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
7.6
HIGHCVE-2024-1097
A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the... Read more
Affected Products : webcalendar- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
6.1
MEDIUMCVE-2024-11182
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail u... Read more
- Actively Exploited
- Published: Nov. 15, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-10534
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects Personnel Attendance Control Systems (PACS) / Access Control Sec... Read more
Affected Products : personnel_attendance_control_systems_\/_access_control_security_systems- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-10443
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attacke... Read more
- Published: Nov. 15, 2024
- Modified: Apr. 10, 2025
-
8.1
HIGHCVE-2024-0875
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient view... Read more
Affected Products : openemr- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.9
MEDIUMCVE-2024-0787
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044... Read more
Affected Products : phpipam- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.9
MEDIUMCVE-2023-4679
A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash... Read more
Affected Products : gpac- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
4.8
MEDIUMCVE-2023-2332
A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the Date Range section, allowing an attacker to inject malicious... Read more
Affected Products : pimcore- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
6.5
MEDIUMCVE-2023-0737
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.... Read more
Affected Products : wallabag- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2023-0109
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is acces... Read more
Affected Products : memos- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
10.0
CRITICALCVE-2022-1884
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` t... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
4.8
MEDIUMCVE-2022-1226
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file upload. T... Read more
Affected Products : phpipam- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024