Latest CVE Feed
-
6.1
MEDIUMCVE-2024-47648
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 14, 2024
-
4.7
MEDIUMCVE-2024-47354
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership After Login Redirection.This issue affects Simple Membership After Login Redirection: from n/a through 1.6.... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.4
MEDIUMCVE-2024-9805
A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/campsdetails.php. The manipulation of the argument hospital/address/city/contact leads to cro... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.8
MEDIUMCVE-2024-9804
A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/campsdetails.php. The manipulation of the argument hospital leads to sql injection. The attack c... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
8.4
HIGHCVE-2024-47966
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47965
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code i... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47964
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute ... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47963
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code ... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47962
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to ex... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
9.8
CRITICALCVE-2024-47636
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 12, 2024
-
5.4
MEDIUMCVE-2024-9803
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file blooddetails.php. The manipulation of the argument Availibility leads to cross site scripting. It ... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
6.1
MEDIUMCVE-2024-9799
A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/... Read more
Affected Products : profile_registration_without_reload\/refresh- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.5
HIGHCVE-2024-9797
A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file register.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attac... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9794
A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing of the file /update-image1.php. The manipulation of the argument productimage1 leads to unrestricted uploa... Read more
Affected Products : online_shopping_portal- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9793
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated r... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 01, 2024
-
9.2
CRITICALCVE-2023-25581
pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability affects systems that store externally controlled values in attributes of the `UserProfile` class from pac4j-... Read more
Affected Products : pac4j- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9792
A vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the component Port Forwarding Page. The manipulation of the argument PortMappingDescription leads to cross site scripting. It is possible ... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 25, 2024
-
7.2
HIGHCVE-2024-9790
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The e... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9789
A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The explo... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9788
A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The explo... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024