Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-8336

    A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. Affected by this vulnerability is an unknown functionality of the file /php-music/classes/Master.php?f=delete_music. The manipulation of the argument id leads to sq... Read more

    Affected Products : music_gallery_site
    • Published: Aug. 30, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-41372

    Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.... Read more

    Affected Products : organizr
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41371

    Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.... Read more

    Affected Products : organizr
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-41370

    Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.... Read more

    Affected Products : organizr
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41351

    bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php... Read more

    Affected Products : bjyadmin
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41350

    bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php... Read more

    Affected Products : bjyadmin
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41348

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php... Read more

    Affected Products : openflights
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41347

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php... Read more

    Affected Products : openflights
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-41346

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php... Read more

    Affected Products : openflights
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-43965

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4.... Read more

    Affected Products : sendgrid
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-6671

    In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.... Read more

    Affected Products : whatsup_gold
    • Published: Aug. 29, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-8389

    Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.... Read more

    Affected Products : firefox
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-44921

    SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.... Read more

    Affected Products : seacms
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-44920

    A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.... Read more

    Affected Products : seacms
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-8380

    A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/delete-account.php of the component Delete Contact Handler. The manipulatio... Read more

    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2024
  • 8.7

    HIGH
    CVE-2024-8004

    A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products : 3dexperience 3dexperience_enovia
    • Published: Sep. 02, 2024
    • Modified: Sep. 04, 2024
  • 8.7

    HIGH
    CVE-2024-7938

    A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products : 3dexperience 3dexperience
    • Published: Sep. 02, 2024
    • Modified: Sep. 04, 2024
  • 6.1

    MEDIUM
    CVE-2024-38858

    Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.... Read more

    Affected Products : checkmk checkmk
    • Published: Sep. 02, 2024
    • Modified: Sep. 04, 2024
  • 6.5

    MEDIUM
    CVE-2024-8365

    Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of c... Read more

    Affected Products : vault
    • Published: Sep. 02, 2024
    • Modified: Sep. 04, 2024
  • 9.8

    CRITICAL
    CVE-2024-44809

    A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user input passed to the "position" GET parameter in the tilt.php script. An attacker can expl... Read more

    Affected Products :
    • Published: Sep. 03, 2024
    • Modified: Sep. 04, 2024
Showing 20 of 291902 Results