Latest CVE Feed
-
8.8
HIGHCVE-2024-9315
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument... Read more
Affected Products : employee_and_visitor_gate_pass_logging_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-9317
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql ... Read more
Affected Products : online_eyewear_shop- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9318
A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-9319
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is poss... Read more
Affected Products : online_timesheet_app- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-9320
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument ... Read more
Affected Products : online_timesheet_app- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
6.9
MEDIUMCVE-2024-9321
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper a... Read more
Affected Products : railway_reservation_system- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
2.9
LOWCVE-2024-8443
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights,... Read more
- Published: Sep. 10, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-9323
A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/action/add_staff.php. The manipulation leads to cross site script... Read more
- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-6596
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.... Read more
- Published: Sep. 10, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-42473
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possi... Read more
Affected Products : openfga- Published: Aug. 12, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9296
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. ... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9295
A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulation of the argument username leads to sql injection. The ... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9328
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /control/edit_client.php. The manipulation of the argument id leads to sql injection. ... Read more
Affected Products : advocate_office_management_system- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-42406
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channel... Read more
- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
4.4
MEDIUMCVE-2024-6876
Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.... Read more
Affected Products : oscat_basic_library- Published: Sep. 10, 2024
- Modified: Oct. 01, 2024
-
7.3
HIGHCVE-2024-41176
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.... Read more
- Published: Aug. 27, 2024
- Modified: Oct. 01, 2024
-
5.7
MEDIUMCVE-2024-8445
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.... Read more
Affected Products :- Published: Sep. 05, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-41725
ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.... Read more
- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
7.5
HIGHCVE-2024-8941
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a p... Read more
Affected Products : scriptcase- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
8.7
HIGHCVE-2024-45862
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.... Read more
- Published: Sep. 19, 2024
- Modified: Sep. 30, 2024