Latest CVE Feed
-
9.8
CRITICALCVE-2024-48411
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.... Read more
Affected Products : online_tours_and_travels_management_system online_tours_\&_travels_management_system- Published: Oct. 15, 2024
- Modified: May. 17, 2025
-
7.5
HIGHCVE-2024-44775
An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.... Read more
Affected Products : kmqtt- Published: Oct. 15, 2024
- Modified: Sep. 04, 2025
-
8.1
HIGHCVE-2024-41311
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.... Read more
- Published: Oct. 15, 2024
- Modified: Mar. 24, 2025
-
4.9
MEDIUMCVE-2024-31955
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possess... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-49195
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair... Read more
- Published: Oct. 15, 2024
- Modified: May. 06, 2025
-
5.1
MEDIUMCVE-2024-44337
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a log... Read more
Affected Products : markdown- Published: Oct. 15, 2024
- Modified: Nov. 14, 2024
-
5.4
MEDIUMCVE-2024-21286
Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-21285
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
Affected Products : banking_liquidity_management- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
7.1
HIGHCVE-2024-21284
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
Affected Products : banking_liquidity_management- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
8.1
HIGHCVE-2024-21283
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. Easily exploitable vulnerability allows low privileged attacker ... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21282
Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
5.3
MEDIUMCVE-2024-21281
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to exploit vulnerability allows high privileged attac... Read more
Affected Products : banking_liquidity_management- Published: Oct. 15, 2024
- Modified: Feb. 10, 2025
-
8.1
HIGHCVE-2024-21280
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP... Read more
Affected Products : service_contracts- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21279
Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compro... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21278
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged a... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21277
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with ne... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21276
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21275
Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
7.5
HIGHCVE-2024-21274
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network acces... Read more
Affected Products : weblogic_server- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
6.0
MEDIUMCVE-2024-21273
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the... Read more
Affected Products : vm_virtualbox- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024