Latest CVE Feed
-
8.1
HIGHCVE-2024-10141
A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The manipulation of the argument SECRET_KEY leads to predictable from observable state. It is ... Read more
Affected Products : coco_annotator- Published: Oct. 19, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-10140
A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. Affected by this issue is some unknown functionality of the file /manage_supplier.php. The manipulation of the argument id leads to sql inje... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-10139
A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add_new_supplier.php. The manipulation of the argument name leads to sql injection. T... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-10138
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. Affected is an unknown function of the file /add_new_purchase.php?action=is_supplier. The manipulation of the argument name leads to sql injection. It i... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-10137
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /manage_medicine.php?action=delete. The manipulation of the argument id leads to sql injection... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-10136
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. T... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
8.8
HIGHCVE-2024-10135
A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects the function actionDelNetSecConfig of the file /com/esafenet/servlet/netSec/NetSecConfigService.java. The manipulation of the argument id leads to sql injection.... Read more
Affected Products : cdg- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
6.4
MEDIUMCVE-2024-9897
The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-twitch-embed shortcode in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping on use... Read more
Affected Products : twitch_integration- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-10134
A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The manipulation of the argument servername leads to sql injection. T... Read more
Affected Products : cdg- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
8.8
HIGHCVE-2024-10133
A vulnerability has been found in ESAFENET CDG 5 and classified as critical. Affected by this vulnerability is the function updateNetSecPolicyPriority of the file /com/esafenet/servlet/ajax/NetSecPolicyAjax.java. The manipulation of the argument id/frontI... Read more
Affected Products : cdg- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
4.3
MEDIUMCVE-2024-9889
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level... Read more
Affected Products : elementinvader_addons_for_elementor- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2023-6243
The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. ... Read more
Affected Products : eventon-lite- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-21536
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the serv... Read more
Affected Products : http-proxy-middleware- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-9219
The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthen... Read more
Affected Products : social_share_buttons- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-10131
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from vari... Read more
Affected Products : ragflow- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
4.9
MEDIUMCVE-2019-25218
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient p... Read more
Affected Products : photo_gallery_slideshow_\&_masonry_tiled_gallery- Published: Oct. 19, 2024
- Modified: Oct. 30, 2024
-
4.3
MEDIUMCVE-2024-43577
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Oct. 18, 2024
- Modified: Jan. 07, 2025
-
9.1
CRITICALCVE-2024-37404
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.... Read more
- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
7.8
HIGHCVE-2024-29821
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.... Read more
Affected Products : desktop_\&_server_management- Published: Oct. 18, 2024
- Modified: Jul. 10, 2025
-
7.8
HIGHCVE-2024-29213
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.... Read more
Affected Products : desktop_\&_server_management- Published: Oct. 18, 2024
- Modified: Jul. 10, 2025