Latest CVE Feed
-
9.8
CRITICALCVE-2024-7581
A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security leads to stack-based buffer overflow. It is possible to... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7005
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium sec... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
4.3
MEDIUMCVE-2024-7003
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6998
Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6997
Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
5.4
MEDIUMCVE-2024-7368
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scri... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7369
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads t... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7370
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the argument id leads to sql injection. It is possible to la... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7371
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quiz_view.php. The manipulation of the argument id leads to sql injectio... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7372
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /quiz_board.php. The manipulation of the argument quiz leads to sql injection. The... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7373
A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-33974
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7441
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-b... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 07, 2024
-
5.4
MEDIUMCVE-2024-7353
The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on use... Read more
Affected Products :- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
8.1
HIGHCVE-2024-2232
The lacks CSRF checks allowing a user to invite any user to any group (including private groups)... Read more
Affected Products : himer- Published: Aug. 05, 2024
- Modified: Aug. 07, 2024
-
7.5
HIGHCVE-2024-41260
A static initialization vector (IV) in the encrypt function of netbird v0.28.4 allows attackers to obtain sensitive information.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7443
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It ... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7439
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buf... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7442
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been rated as critical. This issue affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injec... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7470
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of the file /vpn/vpn_template_style.php of the component Web Interface. The manipulation of... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024