Latest CVE Feed
-
9.8
CRITICALCVE-2024-10730
A vulnerability, which was classified as critical, has been found in Tongda OA up to 11.6. This issue affects some unknown processing of the file /pda/appcenter/web_show.php. The manipulation of the argument ID leads to sql injection. The attack may be in... Read more
Affected Products : office_anywhere- Published: Nov. 03, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-10702
A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attac... Read more
- Published: Nov. 02, 2024
- Modified: Apr. 21, 2025
-
6.1
MEDIUMCVE-2024-10701
A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may ... Read more
Affected Products : car_rental_portal- Published: Nov. 02, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-10700
A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file submit.php. The manipulation of the argument name/email/title/Year/gender/fromdate/tod... Read more
Affected Products : university_event_management_system- Published: Nov. 02, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-10699
A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The manipulation of the argument username leads to sql injection. It is possible to i... Read more
Affected Products : wazifa_system- Published: Nov. 02, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-10698
A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. Th... Read more
- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-10697
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to... Read more
- Published: Nov. 02, 2024
- Modified: Apr. 05, 2025
-
6.1
MEDIUMCVE-2024-9896
The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. Thi... Read more
Affected Products : bbp_core- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
8.1
HIGHCVE-2024-51774
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.... Read more
Affected Products : qbittorrent- Published: Nov. 02, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-9868
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget 'url' parameter in all versions up to, and including, 5.1... Read more
Affected Products : element_pack- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
6.1
MEDIUMCVE-2024-8739
The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for un... Read more
Affected Products : recaptcha_integration- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
6.5
MEDIUMCVE-2024-10540
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form shortcode in all versions up to, and including, 1.1.16 due to insufficien... Read more
Affected Products : bookingpress- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
6.4
MEDIUMCVE-2024-10310
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Widget 'image_title' parameter in all versions up to, and ... Read more
Affected Products : element_pack- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
7.8
HIGHCVE-2024-9191
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnera... Read more
Affected Products : verify- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
6.5
MEDIUMCVE-2024-44234
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file ... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 04, 2024
-
6.5
MEDIUMCVE-2024-44233
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file ... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 04, 2024
-
6.5
MEDIUMCVE-2024-44232
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1, tvOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. Parsing a maliciously crafted video file ... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-51252
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
7.5
HIGHCVE-2024-48353
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.... Read more
Affected Products : yealink_meeting_server- Published: Nov. 01, 2024
- Modified: Mar. 07, 2025
-
8.8
HIGHCVE-2024-51492
Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images allow for unrestricted script execution on (raw) image load. With certain payloads, theft of the target ... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024