Latest CVE Feed
-
5.5
MEDIUMCVE-2023-45315
Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.8
HIGHCVE-2023-45320
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : vtune_profiler- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.8
HIGHCVE-2023-45736
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
5.5
MEDIUMCVE-2023-45846
Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
8.8
HIGHCVE-2023-46689
Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.9
HIGHCVE-2023-46691
Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
8.6
HIGHCVE-2024-9497
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2024-9411
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possibl... Read more
Affected Products : ofcms- Published: Oct. 01, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-9037
A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remot... Read more
Affected Products : internal_marks_calculation- Published: Sep. 20, 2024
- Modified: Aug. 27, 2025
-
6.5
MEDIUMCVE-2024-9036
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be ini... Read more
- Published: Sep. 20, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-9035
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login. The manipulation of the argument username/password lea... Read more
- Published: Sep. 20, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-9034
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The a... Read more
- Published: Sep. 20, 2024
- Modified: Aug. 27, 2025
-
7.2
HIGHCVE-2024-8914
The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 due to incorrect use of the wp_kses_allowed_html functi... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Aug. 27, 2025
-
9.9
CRITICALCVE-2024-8436
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied param... Read more
Affected Products : wp_easy_gallery- Published: Sep. 25, 2024
- Modified: Aug. 27, 2025
-
7.6
HIGHCVE-2024-8058
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Aug. 27, 2025
-
4.3
MEDIUMCVE-2024-6352
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-6163
Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data... Read more
- Published: Jul. 08, 2024
- Modified: Aug. 27, 2025
-
6.5
MEDIUMCVE-2024-56430
OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.... Read more
Affected Products :- Published: Dec. 25, 2024
- Modified: Aug. 27, 2025
-
7.1
HIGHCVE-2024-56056
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through 1.4.3.... Read more
Affected Products : simplecharm- Published: Jan. 07, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-55551
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can fur... Read more
Affected Products : jdbc_driver- Published: Mar. 19, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection