Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-30619

    Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 04, 2024
    • Modified: Apr. 18, 2025
  • 6.1

    MEDIUM
    CVE-2024-30618

    A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 04, 2024
    • Modified: Apr. 18, 2025
  • 5.4

    MEDIUM
    CVE-2024-30617

    A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 04, 2024
    • Modified: Apr. 18, 2025
  • 8.8

    HIGH
    CVE-2024-30616

    Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 04, 2024
    • Modified: Apr. 18, 2025
  • 5.4

    MEDIUM
    CVE-2024-10768

    A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argumen... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 8.8

    HIGH
    CVE-2024-51329

    A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.... Read more

    Affected Products : agile-board
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.1

    MEDIUM
    CVE-2024-51328

    Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.... Read more

    • Published: Nov. 04, 2024
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-51327

    SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.... Read more

    Affected Products : travel_management_system
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-51326

    SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.... Read more

    Affected Products : travel_management_system
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.1

    CRITICAL
    CVE-2024-51127

    An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.... Read more

    Affected Products : hornetq
    • Published: Nov. 04, 2024
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2024-48336

    The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app... Read more

    Affected Products :
    • Published: Nov. 04, 2024
    • Modified: Nov. 04, 2024
  • 6.8

    MEDIUM
    CVE-2024-34887

    Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.... Read more

    Affected Products : bitrix24
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.8

    MEDIUM
    CVE-2024-34883

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.... Read more

    Affected Products : bitrix24
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 6.8

    MEDIUM
    CVE-2024-34882

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.... Read more

    Affected Products : bitrix24
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10766

    A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrest... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-51136

    An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.... Read more

    Affected Products : openimaj
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-48809

    An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function.... Read more

    Affected Products : onos-a1t sdran-in-a-box
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10765

    A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted upload. The attac... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10764

    A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. It is possible to... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
  • 5.9

    MEDIUM
    CVE-2024-51685

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.... Read more

    Affected Products : accordion_title_for_elementor
    • Published: Nov. 04, 2024
    • Modified: Nov. 06, 2024
Showing 20 of 293649 Results