Latest CVE Feed
-
4.3
MEDIUMCVE-2024-43319
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.... Read more
Affected Products : html5_video_player- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8140
A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting... Read more
Affected Products : task_progress_tracker- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8141
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to ... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8142
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross ... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8151
A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It... Read more
Affected Products : interactive_map_with_marker- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8154
A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_book... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8152
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argume... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-8153
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site ... Read more
Affected Products : qr_code_bookmark_system- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8167
A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the atta... Read more
Affected Products : job_portal- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8168
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injectio... Read more
Affected Products : online_bus_reservation_site- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8169
A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be... Read more
Affected Products : online_quiz_site- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-7988
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which ... Read more
Affected Products : thinmanager_thinserver- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.5
HIGHCVE-2024-7987
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ servi... Read more
Affected Products : thinmanager_thinserver- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
10.0
CRITICALCVE-2024-5932
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible fo... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-41773
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.... Read more
Affected Products : global_configuration_management- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-43409
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5... Read more
Affected Products : ghost- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-43406
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This v... Read more
Affected Products : ekuiper- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-43404
MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Pytho... Read more
Affected Products : megabot- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
4.3
MEDIUMCVE-2024-43397
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessar... Read more
Affected Products : apollo- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-43377
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.... Read more
Affected Products : umbraco_cms- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024