Latest CVE Feed
-
10.0
CRITICALCVE-2024-8923
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to h... Read more
Affected Products : servicenow- Published: Oct. 29, 2024
- Modified: Nov. 27, 2024
-
8.8
HIGHCVE-2024-7985
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it... Read more
Affected Products : fileorganizer- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-25566
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks... Read more
Affected Products : access_management- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
2.7
LOWCVE-2024-10452
Organization admins can delete pending invites created in an organization they are not part of.... Read more
Affected Products : grafana- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
8.7
HIGHCVE-2024-50334
Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive... Read more
Affected Products : scoold- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-49769
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread atte... Read more
Affected Products : waitress- Published: Oct. 29, 2024
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2024-49768
Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is disabled (default... Read more
Affected Products : waitress- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
8.7
HIGHCVE-2024-48921
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. A... Read more
Affected Products : kyverno- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
6.4
MEDIUMCVE-2024-9505
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user s... Read more
Affected Products : beaver_builder- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
6.1
MEDIUMCVE-2024-51076
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.... Read more
Affected Products : online_dj_booking_management_system- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
6.1
MEDIUMCVE-2024-51075
A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.... Read more
Affected Products : online_dj_booking_management_system- Published: Oct. 29, 2024
- Modified: Nov. 04, 2024
-
7.1
HIGHCVE-2024-49634
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.... Read more
Affected Products : bp_member_type_manager- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49632
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.... Read more
Affected Products : cwd_3d_image_gallery- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-47640
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.... Read more
Affected Products : wp_erp- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2024-10226
The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products : arconix_shortcodes- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-8309
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deletin... Read more
Affected Products : langchain- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-8143
In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the use... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-7962
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file mus... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-7807
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Jan. 09, 2025
-
7.5
HIGHCVE-2024-7783
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the passw... Read more
Affected Products : anythingllm- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024