Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.4

    MEDIUM
    CVE-2024-10148

    The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This ma... Read more

    Affected Products : awesome_buttons
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 8.1

    HIGH
    CVE-2024-10011

    The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on f... Read more

    Affected Products : buddypress
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-9488

    The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for una... Read more

    Affected Products : wpdiscuz
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 4.3

    MEDIUM
    CVE-2024-9109

    The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.11. This make... Read more

    Affected Products : woocommerce_ups_shipping
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 5.3

    MEDIUM
    CVE-2024-9686

    The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions up to, and including, 1.0.1. This makes it possible for u... Read more

    Affected Products : order_notification_for_telegram
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 4.5

    MEDIUM
    CVE-2024-10372

    A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function download_model of the file buzz/model_loader.py. The manipulation leads to insecure temporary file. It is possible to launch the attac... Read more

    Affected Products : buzz
    • Published: Oct. 25, 2024
    • Modified: Nov. 06, 2024
  • 9.8

    CRITICAL
    CVE-2024-10371

    A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be use... Read more

    Affected Products : payroll_management_system
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 9.8

    CRITICAL
    CVE-2024-10370

    A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack m... Read more

    Affected Products : sales_management_system
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 9.8

    CRITICAL
    CVE-2024-10369

    A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The... Read more

    Affected Products : sales_management_system
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 9.8

    CRITICAL
    CVE-2024-10368

    A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch th... Read more

    Affected Products : sales_management_system
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 5.8

    MEDIUM
    CVE-2024-10355

    A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql ... Read more

    Affected Products : petrol_pump_management
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 5.8

    MEDIUM
    CVE-2024-10354

    A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The manipulation of the argument id leads to sql injection. Th... Read more

    Affected Products : petrol_pump_management
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 7.2

    HIGH
    CVE-2024-10353

    A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the attack remotely.... Read more

    Affected Products : online_exam_system
    • Published: Oct. 25, 2024
    • Modified: Oct. 30, 2024
  • 9.0

    HIGH
    CVE-2024-10351

    A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads ... Read more

    Affected Products : rx9_pro_firmware rx9_pro
    • Published: Oct. 25, 2024
    • Modified: Nov. 01, 2024
  • 9.8

    CRITICAL
    CVE-2024-10350

    A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection. The at... Read more

    • Published: Oct. 24, 2024
    • Modified: Oct. 30, 2024
  • 4.6

    MEDIUM
    CVE-2024-49762

    Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted when usi... Read more

    Affected Products :
    • Published: Oct. 24, 2024
    • Modified: Oct. 25, 2024
  • 7.1

    HIGH
    CVE-2024-49760

    OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versio... Read more

    Affected Products : openrefine
    • Published: Oct. 24, 2024
    • Modified: Nov. 06, 2024
  • 5.5

    MEDIUM
    CVE-2024-49750

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector coul... Read more

    Affected Products : snowflake_connector
    • Published: Oct. 24, 2024
    • Modified: Nov. 06, 2024
  • 7.5

    HIGH
    CVE-2024-49359

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allo... Read more

    Affected Products : zimaos
    • Published: Oct. 24, 2024
    • Modified: Nov. 06, 2024
  • 5.3

    MEDIUM
    CVE-2024-49358

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username e... Read more

    Affected Products : zimaos
    • Published: Oct. 24, 2024
    • Modified: Nov. 06, 2024
Showing 20 of 294354 Results