Latest CVE Feed
-
8.1
HIGHCVE-2024-45058
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, an attacker with only minimal viewing privileges in the settings section is able to chang... Read more
Affected Products : i-educar- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
6.3
MEDIUMCVE-2024-45057
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the dynamic generation of HTML fields prior... Read more
Affected Products : i-educar- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
7.5
HIGHCVE-2024-45442
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 13, 2024
-
6.3
MEDIUMCVE-2024-43797
audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows a pat... Read more
Affected Products : audiobookshelf- Published: Sep. 02, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-7261
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlie... Read more
Affected Products : nwa110ax_firmware nwa1123acv3_firmware nwa210ax_firmware nwa220ax-6e_firmware nwa50ax_firmware nwa55axe_firmware nwa90ax_firmware wac500_firmware wac500h_firmware wac6103d-i_firmware +48 more products- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
5.0
MEDIUMCVE-2024-44685
Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.... Read more
Affected Products : titan_sftp_server- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
5.3
MEDIUMCVE-2024-7447
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'fnsf_af2_handel_file_upload' function in ... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
5.3
MEDIUMCVE-2024-8195
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it po... Read more
Affected Products : permalink_manager_lite- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
5.5
MEDIUMCVE-2024-20503
A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This vulnerability is due to improper storage of an unencrypted registry key. A low-privileg... Read more
Affected Products : duo_authentication_for_epic- Published: Sep. 04, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-8368
A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to... Read more
- Published: Sep. 01, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45615
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45616
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caus... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45617
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
6.4
MEDIUMCVE-2024-8276
The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg block in all versions up to, and including, 1.4.4 due to insufficie... Read more
Affected Products : wpzoom_portfolio- Published: Aug. 31, 2024
- Modified: Sep. 13, 2024
-
9.1
CRITICALCVE-2024-7856
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'f... Read more
Affected Products : mp3_audio_player_for_music\,_radio_\&_podcast- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024
-
8.1
HIGHCVE-2021-22509
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
7.2
HIGHCVE-2021-38120
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version b... Read more
Affected Products : netiq_advanced_authentication netiq_advance_authentication netiq_advance_authentication- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
8.8
HIGHCVE-2021-38121
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
8.2
HIGHCVE-2021-38122
A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
6.3
MEDIUMCVE-2021-22529
A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024