Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2024-27525

    Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 01, 2024
    • Modified: Apr. 18, 2025
  • 7.1

    HIGH
    CVE-2024-27524

    Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.... Read more

    Affected Products : chamilo_lms
    • Published: Nov. 01, 2024
    • Modified: Apr. 17, 2025
  • 9.8

    CRITICAL
    CVE-2024-10658

    A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack ca... Read more

    Affected Products : office_anywhere
    • Published: Nov. 01, 2024
    • Modified: Nov. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-10657

    A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation of the argument RUN_ID leads to sql injection. It is possible to launch the att... Read more

    Affected Products : office_anywhere
    • Published: Nov. 01, 2024
    • Modified: Nov. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-10656

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the file /pda/meeting/apply.php. The manipulation of the argument mr_id leads to sql injection. The attack may be initiate... Read more

    • Published: Nov. 01, 2024
    • Modified: Nov. 04, 2024
  • 6.2

    MEDIUM
    CVE-2024-51407

    Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies.... Read more

    Affected Products : floodlight
    • Published: Nov. 01, 2024
    • Modified: May. 27, 2025
  • 6.2

    MEDIUM
    CVE-2024-51406

    Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.... Read more

    Affected Products : floodlight open_sdn_controller
    • Published: Nov. 01, 2024
    • Modified: Jun. 11, 2025
  • 7.5

    HIGH
    CVE-2024-48270

    An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.... Read more

    Affected Products : oasys
    • Published: Nov. 01, 2024
    • Modified: Jul. 07, 2025
  • 9.8

    CRITICAL
    CVE-2024-37094

    Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.... Read more

    Affected Products : masterstudy_lms
    • Published: Nov. 01, 2024
    • Modified: Jan. 22, 2025
  • 9.8

    CRITICAL
    CVE-2024-10655

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file /pda/reportshop/new.php. The manipulation of the argument repid leads to sql injection. The attack can be initiat... Read more

    • Published: Nov. 01, 2024
    • Modified: Nov. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-7456

    A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is... Read more

    Affected Products : lunary
    • Published: Nov. 01, 2024
    • Modified: Nov. 06, 2024
  • 9.1

    CRITICAL
    CVE-2024-10654

    A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to a... Read more

    Affected Products : lr350_firmware
    • Published: Nov. 01, 2024
    • Modified: Nov. 05, 2024
  • 6.4

    MEDIUM
    CVE-2024-10367

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization... Read more

    Affected Products : otter_blocks
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 7.2

    HIGH
    CVE-2024-10653

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-10652

    IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks.... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 4.9

    MEDIUM
    CVE-2024-10651

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files.... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 6.4

    MEDIUM
    CVE-2024-10232

    The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user su... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 6.4

    MEDIUM
    CVE-2024-9655

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output... Read more

    Affected Products : gutenberg_blocks_with_ai
    • Published: Nov. 01, 2024
    • Modified: Feb. 07, 2025
  • 5.4

    MEDIUM
    CVE-2024-7424

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for a... Read more

    Affected Products :
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
  • 8.7

    HIGH
    CVE-2024-0106

    NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service... Read more

    Affected Products : bluefield_1_firmware
    • Published: Nov. 01, 2024
    • Modified: Nov. 01, 2024
Showing 20 of 293639 Results