Latest CVE Feed
-
5.3
MEDIUMCVE-2024-47586
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and r... Read more
Affected Products : netweaver_application_server_abap- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-42372
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-11096
A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation of the argument projectName leads to sql injection. It is possible to initiate the a... Read more
Affected Products : task_manager- Published: Nov. 12, 2024
- Modified: Nov. 23, 2024
-
5.5
MEDIUMCVE-2024-11079
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outpu... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.... Read more
- Published: Nov. 11, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2024-51213
Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-50636
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 19, 2024
-
6.1
MEDIUMCVE-2024-50601
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further ... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-25255
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Dec. 24, 2024
-
9.8
CRITICALCVE-2024-25254
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.... Read more
Affected Products : superscan- Published: Nov. 11, 2024
- Modified: Jun. 24, 2025
-
7.5
HIGHCVE-2024-25253
Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 19, 2024
-
5.8
MEDIUMCVE-2024-23983
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.... Read more
Affected Products : pingaccess- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
5.4
MEDIUMCVE-2024-51026
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-46966
The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-46964
The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-46963
The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.1
CRITICALCVE-2024-46962
The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-44546
Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.... Read more
Affected Products : powerjob- Published: Nov. 11, 2024
- Modified: Jun. 27, 2025
-
7.5
HIGHCVE-2024-52532
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.4
HIGHCVE-2024-52531
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application ma... Read more
Affected Products : libsoup- Published: Nov. 11, 2024
- Modified: Aug. 27, 2025