Latest CVE Feed
-
8.8
HIGHCVE-2024-47846
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
Affected Products : cargo- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
8.2
HIGHCVE-2024-47845
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2... Read more
Affected Products : wikimedia-extensions-css- Published: Oct. 05, 2024
- Modified: Oct. 23, 2024
-
6.9
MEDIUMCVE-2024-47840
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X ... Read more
Affected Products : apex- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
6.9
MEDIUMCVE-2024-47848
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.3
MEDIUMCVE-2024-47913
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view t... Read more
- Published: Oct. 04, 2024
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2024-47911
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.... Read more
Affected Products : sonarqube- Published: Oct. 04, 2024
- Modified: Sep. 04, 2025
-
7.2
HIGHCVE-2024-47910
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.... Read more
Affected Products :- Published: Oct. 04, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-37869
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable... Read more
Affected Products : online_discussion_forum- Published: Oct. 04, 2024
- Modified: Oct. 08, 2024
-
8.8
HIGHCVE-2024-37868
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.... Read more
Affected Products : online_discussion_forum- Published: Oct. 04, 2024
- Modified: Oct. 08, 2024
-
8.8
HIGHCVE-2024-9054
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue... Read more
- Published: Oct. 04, 2024
- Modified: Aug. 29, 2025
-
6.5
MEDIUMCVE-2024-7801
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 17, 2024
-
6.9
MEDIUMCVE-2024-47764
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alte... Read more
Affected Products : cookie- Published: Oct. 04, 2024
- Modified: Oct. 07, 2024
-
7.7
HIGHCVE-2024-43687
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 16, 2024
-
6.1
MEDIUMCVE-2024-43686
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-43685
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.... Read more
- Published: Oct. 04, 2024
- Modified: Aug. 29, 2025
-
8.8
HIGHCVE-2024-43684
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.... Read more
- Published: Oct. 04, 2024
- Modified: Aug. 29, 2025
-
8.7
HIGHCVE-2024-43683
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-46078
itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.... Read more
- Published: Oct. 04, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-46077
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.... Read more
Affected Products : online_tours_and_travels_management_system online_tours_and_travels_management_system- Published: Oct. 04, 2024
- Modified: Apr. 28, 2025
-
6.5
MEDIUMCVE-2023-26771
Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious pict... Read more
Affected Products : taskcafe- Published: Oct. 04, 2024
- Modified: May. 27, 2025