Latest CVE Feed
-
5.4
MEDIUMCVE-2024-39837
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.... Read more
- Published: Aug. 01, 2024
- Modified: Sep. 04, 2024
-
8.8
HIGHCVE-2024-7871
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.... Read more
Affected Products : easytest_online_test_platform- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
4.3
MEDIUMCVE-2024-39839
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrar... Read more
- Published: Aug. 01, 2024
- Modified: Sep. 04, 2024
-
5.4
MEDIUMCVE-2024-45046
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information such as font names, allowing an attacker to inject arbitrary Java... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 04, 2024
-
8.8
HIGHCVE-2024-45048
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reportin... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 04, 2024
-
7.1
HIGHCVE-2024-41144
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels... Read more
- Published: Aug. 01, 2024
- Modified: Sep. 04, 2024
-
5.5
MEDIUMCVE-2024-28044
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
8.8
HIGHCVE-2024-8327
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database c... Read more
Affected Products : easy_test_online_learning_and_testing_platform- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
5.4
MEDIUMCVE-2024-8328
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scr... Read more
Affected Products : easy_test_online_learning_and_testing_platform- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
5.5
MEDIUMCVE-2024-38382
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
4.3
MEDIUMCVE-2024-41162
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel rea... Read more
- Published: Aug. 01, 2024
- Modified: Sep. 04, 2024
-
8.4
HIGHCVE-2024-38386
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
4.3
MEDIUMCVE-2024-41926
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was... Read more
- Published: Aug. 01, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-45509
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.... Read more
Affected Products : misp- Published: Sep. 01, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-45508
HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.... Read more
Affected Products : htmldoc- Published: Sep. 01, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-8348
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of th... Read more
- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-8347
A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file /classes/Master.php?f=delete_record. The manipulation of the argument id... Read more
- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
5.5
MEDIUMCVE-2024-39612
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-8346
A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument na... Read more
- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-8345
A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The at... Read more
Affected Products : music_gallery_site- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024