| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27185 | Cri | 0.59 | 9.1 | 0.00 | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. | ||
| CVE-2024-43404 | Cri | 0.00 | 9.8 | 0.01 | Aug 20, 2024 | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the… | ||
| CVE-2024-35540 | Cri | 0.62 | 9.0 | 0.03 | Aug 20, 2024 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2024-30949 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function. | ||
| CVE-2024-33872 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2024 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges. | ||
| CVE-2024-42575 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php. | ||
| CVE-2024-42574 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php. | ||
| CVE-2024-42573 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php. | ||
| CVE-2024-42572 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php. | ||
| CVE-2024-42571 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php. | ||
| CVE-2024-42570 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php. | ||
| CVE-2024-42569 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php. | ||
| CVE-2024-42568 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php. | ||
| CVE-2024-42567 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2. | ||
| CVE-2024-42566 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php | ||
| CVE-2024-42565 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete. | ||
| CVE-2024-42563 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file. | ||
| CVE-2024-42562 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | ||
| CVE-2024-42559 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password. | ||
| CVE-2024-42558 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php. | ||
| CVE-2024-42556 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php. | ||
| CVE-2024-43202 | Cri | 0.57 | 9.8 | 0.02 | Aug 20, 2024 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | ||
| CVE-2024-6847 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. | ||
| CVE-2024-7777 | Cri | 0.59 | 9.0 | 0.01 | Aug 20, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to… | ||
| CVE-2024-5932 | Cri | 0.74 | 10.0 | 0.77 | Aug 20, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated… | ||
| CVE-2024-43354 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. | ||
| CVE-2024-43311 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2024 | Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2. | ||
| CVE-2024-42815 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2024 | In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary… | ||
| CVE-2024-42813 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2024 | In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | ||
| CVE-2024-42812 | Cri | 0.65 | 9.8 | 0.16 | Aug 19, 2024 | In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | ||
| CVE-2024-43261 | Cri | 0.62 | 9.6 | 0.01 | Aug 19, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1. | ||
| CVE-2024-43252 | Cri | 0.59 | 9.0 | 0.00 | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1. | ||
| CVE-2024-43249 | Cri | 0.64 | 9.9 | 0.01 | Aug 19, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4. | ||
| CVE-2024-43245 | Cri | 0.64 | 9.8 | 0.00 | Aug 19, 2024 | Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4. | ||
| CVE-2024-43242 | Cri | 0.59 | 9.0 | 0.01 | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | ||
| CVE-2024-43401 | Cri | 0.59 | 9.0 | 0.01 | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights… | ||
| CVE-2024-43400 | Cri | 0.52 | 9.0 | 0.00 | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to… | ||
| CVE-2024-43240 | Cri | 0.61 | 9.4 | 0.01 | Aug 19, 2024 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | ||
| CVE-2024-42658 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2024 | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter | ||
| CVE-2024-37099 | Cri | 0.65 | 10.0 | 0.01 | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1. | ||
| CVE-2024-6330 | Cri | 0.64 | 9.8 | 0.02 | Aug 19, 2024 | The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution. | ||
| CVE-2024-44076 | Cri | 0.57 | 9.8 | 0.01 | Aug 19, 2024 | In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access. | ||
| CVE-2024-42285 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with an existing struct iw_cm_id (cm_id) as follows: … | ||
| CVE-2024-42284 | Cri | 0.59 | 9.1 | 0.01 | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can occur in… | ||
| CVE-2024-6459 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2024 | The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in… | ||
| CVE-2024-6500 | Cri | 0.65 | 10.0 | 0.01 | Aug 17, 2024 | The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as… | ||
| CVE-2024-43042 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. | ||
| CVE-2024-42850 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements. | ||
| CVE-2024-42639 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root. | |
| CVE-2024-42638 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2024 | H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. |
- risk 0.59cvss 9.1epss 0.00
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
- risk 0.00cvss 9.8epss 0.01
MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the…
- risk 0.62cvss 9.0epss 0.03
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function.
- risk 0.64cvss 9.8epss 0.00
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
- risk 0.64cvss 9.8epss 0.01
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
- risk 0.64cvss 9.8epss 0.01
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
- risk 0.64cvss 9.8epss 0.01
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
- risk 0.64cvss 9.8epss 0.01
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
- risk 0.57cvss 9.8epss 0.02
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
- risk 0.64cvss 9.8epss 0.01
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
- risk 0.59cvss 9.0epss 0.01
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functions in versions 2.0 to…
- risk 0.74cvss 10.0epss 0.77
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated…
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
- risk 0.64cvss 9.8epss 0.00
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.
- risk 0.64cvss 9.8epss 0.01
In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary…
- risk 0.64cvss 9.8epss 0.01
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
- risk 0.65cvss 9.8epss 0.16
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
- risk 0.62cvss 9.6epss 0.01
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.
- risk 0.59cvss 9.0epss 0.00
Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.
- risk 0.64cvss 9.9epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4.
- risk 0.64cvss 9.8epss 0.00
Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.
- risk 0.59cvss 9.0epss 0.01
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
- risk 0.59cvss 9.0epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights…
- risk 0.52cvss 9.0epss 0.00
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to…
- risk 0.61cvss 9.4epss 0.01
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
- risk 0.64cvss 9.8epss 0.01
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
- risk 0.65cvss 10.0epss 0.01
Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.
- risk 0.64cvss 9.8epss 0.02
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.
- risk 0.57cvss 9.8epss 0.01
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
- risk 0.64cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with an existing struct iw_cm_id (cm_id) as follows: …
- risk 0.59cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can occur in…
- risk 0.64cvss 9.8epss 0.01
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in…
- risk 0.65cvss 10.0epss 0.01
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as…
- risk 0.64cvss 9.8epss 0.01
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
- risk 0.64cvss 9.8epss 0.01
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
- risk 0.64cvss 9.8epss 0.01
H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.01
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.