Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    CRITICAL
    CVE-2024-8923

    ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to h... Read more

    Affected Products : servicenow
    • Published: Oct. 29, 2024
    • Modified: Nov. 27, 2024
  • 8.8

    HIGH
    CVE-2024-7985

    The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it... Read more

    Affected Products : fileorganizer
    • Published: Oct. 29, 2024
    • Modified: Nov. 08, 2024
  • 6.1

    MEDIUM
    CVE-2024-25566

    An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks... Read more

    Affected Products : access_management
    • Published: Oct. 29, 2024
    • Modified: Nov. 08, 2024
  • 2.7

    LOW
    CVE-2024-10452

    Organization admins can delete pending invites created in an organization they are not part of.... Read more

    Affected Products : grafana
    • Published: Oct. 29, 2024
    • Modified: Nov. 08, 2024
  • 8.7

    HIGH
    CVE-2024-50334

    Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive... Read more

    Affected Products : scoold
    • Published: Oct. 29, 2024
    • Modified: Nov. 08, 2024
  • 7.5

    HIGH
    CVE-2024-49769

    Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread atte... Read more

    Affected Products : waitress
    • Published: Oct. 29, 2024
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2024-49768

    Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is disabled (default... Read more

    Affected Products : waitress
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 8.7

    HIGH
    CVE-2024-48921

    Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. A... Read more

    Affected Products : kyverno
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 6.4

    MEDIUM
    CVE-2024-9505

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user s... Read more

    Affected Products : beaver_builder
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 6.1

    MEDIUM
    CVE-2024-51076

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.... Read more

    • Published: Oct. 29, 2024
    • Modified: Nov. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-51075

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.... Read more

    • Published: Oct. 29, 2024
    • Modified: Nov. 04, 2024
  • 7.1

    HIGH
    CVE-2024-49634

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.... Read more

    Affected Products : bp_member_type_manager
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-49632

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.... Read more

    Affected Products : cwd_3d_image_gallery
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-47640

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.... Read more

    Affected Products : wp_erp
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 6.4

    MEDIUM
    CVE-2024-10226

    The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more

    Affected Products : arconix_shortcodes
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-8309

    A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deletin... Read more

    Affected Products : langchain
    • Published: Oct. 29, 2024
    • Modified: Nov. 01, 2024
  • 6.5

    MEDIUM
    CVE-2024-8143

    In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the use... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.5

    HIGH
    CVE-2024-7962

    An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file mus... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Nov. 01, 2024
  • 7.5

    HIGH
    CVE-2024-7807

    A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Jan. 09, 2025
  • 7.5

    HIGH
    CVE-2024-7783

    mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the passw... Read more

    Affected Products : anythingllm
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
Showing 20 of 293680 Results