Latest CVE Feed
-
8.8
HIGHCVE-2024-42786
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42785
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-42784
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
4.1
MEDIUMCVE-2024-41849
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41848
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41847
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41846
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-45258
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.... Read more
Affected Products :- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
7.3
HIGHCVE-2024-43688
cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.... Read more
- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41845
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41844
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41843
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
4.8
MEDIUMCVE-2024-41842
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41841
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-44382
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-44381
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-45256
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add i... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8161
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve ... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-7656
The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of untrusted input in the 'devvn_ihotspot_shortcode_func' function. This makes it possible for authentica... Read more
Affected Products :- Published: Aug. 24, 2024
- Modified: Aug. 26, 2024
-
4.9
MEDIUMCVE-2024-43443
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024