Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-48781

    An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.... Read more

    Affected Products :
    • Published: Oct. 15, 2024
    • Modified: Oct. 16, 2024
  • 9.8

    CRITICAL
    CVE-2024-48779

    An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.... Read more

    Affected Products :
    • Published: Oct. 15, 2024
    • Modified: Oct. 17, 2024
  • 6.5

    MEDIUM
    CVE-2024-48714

    In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more

    Affected Products : tl-wdr7660_firmware tl-wdr7660
    • Published: Oct. 15, 2024
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2024-48713

    In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more

    Affected Products : tl-wdr7660_firmware tl-wdr7660
    • Published: Oct. 15, 2024
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2024-48712

    In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more

    Affected Products : tl-wdr7660_firmware tl-wdr7660
    • Published: Oct. 15, 2024
    • Modified: May. 21, 2025
  • 6.5

    MEDIUM
    CVE-2024-48710

    In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more

    Affected Products : tl-wdr7660_firmware tl-wdr7660
    • Published: Oct. 15, 2024
    • Modified: May. 21, 2025
  • 9.8

    CRITICAL
    CVE-2024-48411

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.... Read more

    • Published: Oct. 15, 2024
    • Modified: May. 17, 2025
  • 7.5

    HIGH
    CVE-2024-44775

    An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.... Read more

    Affected Products : kmqtt
    • Published: Oct. 15, 2024
    • Modified: Sep. 04, 2025
  • 8.1

    HIGH
    CVE-2024-41311

    In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.... Read more

    Affected Products : debian_linux libheif
    • Published: Oct. 15, 2024
    • Modified: Mar. 24, 2025
  • 4.9

    MEDIUM
    CVE-2024-31955

    An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possess... Read more

    Affected Products :
    • Published: Oct. 15, 2024
    • Modified: Oct. 30, 2024
  • 9.8

    CRITICAL
    CVE-2024-49195

    Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair... Read more

    Affected Products : mbed_tls mbedtls
    • Published: Oct. 15, 2024
    • Modified: May. 06, 2025
  • 5.1

    MEDIUM
    CVE-2024-44337

    The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a log... Read more

    Affected Products : markdown
    • Published: Oct. 15, 2024
    • Modified: Nov. 14, 2024
  • 5.4

    MEDIUM
    CVE-2024-21286

    Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged... Read more

    • Published: Oct. 15, 2024
    • Modified: Oct. 21, 2024
  • 7.1

    HIGH
    CVE-2024-21285

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more

    Affected Products : banking_liquidity_management
    • Published: Oct. 15, 2024
    • Modified: Oct. 18, 2024
  • 7.1

    HIGH
    CVE-2024-21284

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more

    Affected Products : banking_liquidity_management
    • Published: Oct. 15, 2024
    • Modified: Oct. 18, 2024
  • 8.1

    HIGH
    CVE-2024-21283

    Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. Easily exploitable vulnerability allows low privileged attacker ... Read more

    • Published: Oct. 15, 2024
    • Modified: Oct. 21, 2024
  • 8.1

    HIGH
    CVE-2024-21282

    Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTT... Read more

    Affected Products : e-business_suite financials
    • Published: Oct. 15, 2024
    • Modified: Oct. 21, 2024
  • 5.3

    MEDIUM
    CVE-2024-21281

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to exploit vulnerability allows high privileged attac... Read more

    Affected Products : banking_liquidity_management
    • Published: Oct. 15, 2024
    • Modified: Feb. 10, 2025
  • 8.1

    HIGH
    CVE-2024-21280

    Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP... Read more

    Affected Products : service_contracts
    • Published: Oct. 15, 2024
    • Modified: Oct. 21, 2024
  • 8.1

    HIGH
    CVE-2024-21279

    Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compro... Read more

    Affected Products : e-business_suite sourcing
    • Published: Oct. 15, 2024
    • Modified: Oct. 21, 2024
Showing 20 of 294848 Results