Latest CVE Feed
-
9.8
CRITICALCVE-2024-51065
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.... Read more
Affected Products : beauty_parlour_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2024-51064
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.... Read more
Affected Products : teachers_record_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.1
CRITICALCVE-2024-51063
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.... Read more
Affected Products : teachers_record_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.1
CRITICALCVE-2024-51060
Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.... Read more
- Published: Oct. 31, 2024
- Modified: May. 06, 2025
-
6.0
MEDIUMCVE-2024-50802
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.... Read more
Affected Products : abantecart- Published: Oct. 31, 2024
- Modified: Sep. 04, 2025
-
6.0
MEDIUMCVE-2024-50801
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.... Read more
Affected Products : abantecart- Published: Oct. 31, 2024
- Modified: Sep. 04, 2025
-
8.4
HIGHCVE-2024-48200
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.9
CRITICALCVE-2024-42515
Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored ... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-39332
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.... Read more
Affected Products : webswing- Published: Oct. 31, 2024
- Modified: Jul. 10, 2025
-
6.7
MEDIUMCVE-2024-10573
An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The c... Read more
Affected Products : enterprise_linux- Published: Oct. 31, 2024
- Modified: Dec. 18, 2024
-
6.1
MEDIUMCVE-2023-52045
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.... Read more
Affected Products : elfinder- Published: Oct. 31, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2023-52044
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.... Read more
Affected Products : elfinder- Published: Oct. 31, 2024
- Modified: Apr. 17, 2025
-
9.9
CRITICALCVE-2024-51482
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This is fixed in 1.37.65.... Read more
Affected Products : zoneminder- Published: Oct. 31, 2024
- Modified: Nov. 05, 2024
-
0.0
NONECVE-2024-50356
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn'... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
6.3
MEDIUMCVE-2024-50347
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in ... Read more
Affected Products : laravel- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
3.7
LOWCVE-2024-7883
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first us... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
1.0
LOWCVE-2024-51481
Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were not executed in the macOS sandbox. Thus, these builders (which are running under th... Read more
- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.9
CRITICALCVE-2024-51478
YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.... Read more
Affected Products : yeswiki- Published: Oct. 31, 2024
- Modified: May. 09, 2025
-
6.4
MEDIUMCVE-2024-51430
Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name parameter on the diagnostic/add-test.php component.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-8185
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of... Read more
- Published: Oct. 31, 2024
- Modified: Aug. 07, 2025