Latest CVE Feed
-
5.4
MEDIUMCVE-2024-7942
A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The manipulation of the argument phone_number leads to cross site scripting. The a... Read more
Affected Products : leads_manager_tool- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
8.8
HIGHCVE-2024-7943
A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. The manipulation of the argument file leads to unrestricted upload. T... Read more
Affected Products : laravel_property_management_system- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
6.4
MEDIUMCVE-2024-5763
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, an... Read more
Affected Products : the_plus_addons_for_elementor- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
6.4
MEDIUMCVE-2024-6575
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all ve... Read more
Affected Products : the_plus_addons_for_elementor- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
6.4
MEDIUMCVE-2024-6864
The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output ... Read more
Affected Products : wp_last_modified_info- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
6.1
MEDIUMCVE-2024-41697
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)... Read more
Affected Products : priority- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-41698
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products : priority- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-41699
Priority – CWE-552: Files or Directories Accessible to External Parties... Read more
Affected Products : priority- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-41518
An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.... Read more
Affected Products : feripro- Published: Aug. 02, 2024
- Modified: Sep. 03, 2024
-
4.9
MEDIUMCVE-2024-43803
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kubernetes Secrets. ... Read more
Affected Products : baremetal_operator- Published: Sep. 03, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-41700
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products : sip_client_firmware- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-42941
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-42940
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Sep. 03, 2024
-
6.1
MEDIUMCVE-2024-41241
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.... Read more
Affected Products : responsive_school_management_system- Published: Aug. 07, 2024
- Modified: Sep. 03, 2024
-
5.4
MEDIUMCVE-2024-40473
A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.... Read more
Affected Products : best_house_rental_management_system- Published: Aug. 12, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-33892
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3... Read more
- Published: Aug. 02, 2024
- Modified: Sep. 03, 2024
-
6.1
MEDIUMCVE-2024-3886
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_check_envato... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-42987
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the modino parameter in the fromPptpUserAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Sep. 03, 2024
-
7.5
HIGHCVE-2024-42948
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Sep. 03, 2024
-
9.8
CRITICALCVE-2024-42568
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.... Read more
Affected Products : school_management_system- Published: Aug. 20, 2024
- Modified: Sep. 03, 2024