Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.7

    HIGH
    CVE-2024-50334

    Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive... Read more

    Affected Products : scoold
    • Published: Oct. 29, 2024
    • Modified: Nov. 08, 2024
  • 7.5

    HIGH
    CVE-2024-49769

    Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread atte... Read more

    Affected Products : waitress
    • Published: Oct. 29, 2024
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2024-49768

    Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is disabled (default... Read more

    Affected Products : waitress
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 8.7

    HIGH
    CVE-2024-48921

    Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. A... Read more

    Affected Products : kyverno
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 6.4

    MEDIUM
    CVE-2024-9505

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user s... Read more

    Affected Products : beaver_builder
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 6.1

    MEDIUM
    CVE-2024-51076

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.... Read more

    • Published: Oct. 29, 2024
    • Modified: Nov. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-51075

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.... Read more

    • Published: Oct. 29, 2024
    • Modified: Nov. 04, 2024
  • 7.1

    HIGH
    CVE-2024-49634

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.... Read more

    Affected Products : bp_member_type_manager
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-49632

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.... Read more

    Affected Products : cwd_3d_image_gallery
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.1

    HIGH
    CVE-2024-47640

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.... Read more

    Affected Products : wp_erp
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 6.4

    MEDIUM
    CVE-2024-10226

    The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more

    Affected Products : arconix_shortcodes
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 9.8

    CRITICAL
    CVE-2024-8309

    A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deletin... Read more

    Affected Products : langchain
    • Published: Oct. 29, 2024
    • Modified: Nov. 01, 2024
  • 6.5

    MEDIUM
    CVE-2024-8143

    In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the use... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 7.5

    HIGH
    CVE-2024-7962

    An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file mus... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Nov. 01, 2024
  • 7.5

    HIGH
    CVE-2024-7807

    A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process... Read more

    Affected Products : chuanhuchatgpt
    • Published: Oct. 29, 2024
    • Modified: Jan. 09, 2025
  • 7.5

    HIGH
    CVE-2024-7783

    mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the passw... Read more

    Affected Products : anythingllm
    • Published: Oct. 29, 2024
    • Modified: Oct. 31, 2024
  • 9.1

    CRITICAL
    CVE-2024-7774

    A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. ... Read more

    Affected Products : langchain langchain.js
    • Published: Oct. 29, 2024
    • Modified: May. 28, 2025
  • 9.1

    CRITICAL
    CVE-2024-7475

    An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation of authentication processes, fraudulent login requests, and t... Read more

    Affected Products : lunary
    • Published: Oct. 29, 2024
    • Modified: Nov. 04, 2024
  • 9.1

    CRITICAL
    CVE-2024-7474

    In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' parameter in the request URL. The application does not perform adequate checks on the ... Read more

    Affected Products : lunary
    • Published: Oct. 29, 2024
    • Modified: Jan. 09, 2025
  • 7.5

    HIGH
    CVE-2024-7473

    An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update other users' prompts by manipulating the 'id' parameter in the request... Read more

    Affected Products : lunary
    • Published: Oct. 29, 2024
    • Modified: Nov. 03, 2024
Showing 20 of 293696 Results