Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2024-40476

    A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as ... Read more

    • Published: Aug. 12, 2024
    • Modified: Aug. 15, 2024
  • 8.8

    HIGH
    CVE-2024-40475

    SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.... Read more

    • Published: Aug. 12, 2024
    • Modified: Aug. 15, 2024
  • 8.8

    HIGH
    CVE-2024-40474

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.... Read more

    • Published: Aug. 12, 2024
    • Modified: Aug. 15, 2024
  • 9.8

    CRITICAL
    CVE-2024-40472

    Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."... Read more

    Affected Products : daily_calories_monitoring_tool
    • Published: Aug. 12, 2024
    • Modified: Aug. 15, 2024
  • 9.8

    CRITICAL
    CVE-2024-7462

    A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to buffer overflow. It is possible to init... Read more

    Affected Products : n350rt_firmware n350rt
    • Published: Aug. 05, 2024
    • Modified: Aug. 15, 2024
  • 9.8

    CRITICAL
    CVE-2024-7463

    A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be ini... Read more

    Affected Products : cp900_firmware cp900
    • Published: Aug. 05, 2024
    • Modified: Aug. 15, 2024
  • 9.8

    CRITICAL
    CVE-2024-7464

    A vulnerability, which was classified as critical, has been found in TOTOLINK CP900 6.3c.566. This issue affects the function setTelnetCfg of the component Telnet Service. The manipulation of the argument telnet_enabled leads to command injection. The att... Read more

    Affected Products : cp900_firmware cp900
    • Published: Aug. 05, 2024
    • Modified: Aug. 15, 2024
  • 9.8

    CRITICAL
    CVE-2024-7465

    A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. It is possible ... Read more

    Affected Products : cp450_firmware cp450
    • Published: Aug. 05, 2024
    • Modified: Aug. 15, 2024
  • 8.8

    HIGH
    CVE-2024-40465

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file... Read more

    Affected Products : beego
    • Published: Jul. 31, 2024
    • Modified: Aug. 15, 2024
  • 8.8

    HIGH
    CVE-2024-40464

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file... Read more

    Affected Products : beego
    • Published: Jul. 31, 2024
    • Modified: Aug. 15, 2024
  • 8.6

    HIGH
    CVE-2024-6078

    CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over... Read more

    Affected Products :
    • Published: Aug. 14, 2024
    • Modified: Aug. 15, 2024
  • 6.5

    MEDIUM
    CVE-2024-43368

    The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in place for GHSA-qjqp-xr96-cj99. In pull request 1149, sanitation was added for Trix attachments with a `text/html` ... Read more

    Affected Products :
    • Published: Aug. 14, 2024
    • Modified: Aug. 15, 2024
  • 5.3

    MEDIUM
    CVE-2024-7411

    The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it ... Read more

    Affected Products : newsletters
    • Published: Aug. 15, 2024
    • Modified: Aug. 15, 2024
  • 6.4

    MEDIUM
    CVE-2024-22278

    Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.... Read more

    Affected Products : harbor
    • Published: Aug. 02, 2024
    • Modified: Aug. 14, 2024
  • 8.7

    HIGH
    CVE-2024-41904

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to c... Read more

    Affected Products : sinec_traffic_analyzer
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 7.5

    HIGH
    CVE-2024-41903

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's... Read more

    Affected Products : sinec_traffic_analyzer
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.9

    MEDIUM
    CVE-2024-41683

    A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords.... Read more

    Affected Products : location_intelligence
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.9

    MEDIUM
    CVE-2024-41682

    A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated remote attacker to conduct brute fo... Read more

    Affected Products : location_intelligence
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 7.5

    HIGH
    CVE-2024-41681

    A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attacker in an on-path position to to rea... Read more

    Affected Products : location_intelligence
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 8.5

    HIGH
    CVE-2024-36398

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.... Read more

    Affected Products : sinec_nms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
Showing 20 of 290013 Results