CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-46921

    Last Modified: 20 Jun 2025

    An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).

    Published: 13 Jan 2025
    4.3
    Medium

    CVE-2024-48883

    Last Modified: 20 Jun 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The UE incorrectly handles a malformed uplink scheduling message, resulting in an information leak of the UE.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42236

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.

    Published: 13 Jan 2025
    7.5
    High

    CVE-2023-42225

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

    Published: 13 Jan 2025
    7.5
    High

    CVE-2023-42226

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.

    Published: 13 Jan 2025
    7.5
    High

    CVE-2023-42227

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.

    Published: 13 Jan 2025
    8.8
    High

    CVE-2023-42228

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42230

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

    Published: 13 Jan 2025
    8.1
    High

    CVE-2023-42231

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.

    Published: 13 Jan 2025
    7.5
    High

    CVE-2023-42232

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42233

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

    Published: 13 Jan 2025
    5.4
    Medium

    CVE-2023-42234

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42235

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42238

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42239

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42240

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42241

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42242

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.

    Published: 13 Jan 2025
    5.4
    Medium

    CVE-2023-42243

    Last Modified: 17 Apr 2025

    In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42245

    Last Modified: 17 Apr 2025

    Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42246

    Last Modified: 17 Apr 2025

    Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42247

    Last Modified: 17 Apr 2025

    Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2023-42248

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42249

    Last Modified: 17 Apr 2025

    Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2023-42250

    Last Modified: 17 Apr 2025

    Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.

    Published: 13 Jan 2025
    7.2
    High

    CVE-2024-46481

    Last Modified: 3 Oct 2025

    The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

    Published: 13 Jan 2025
    9.9
    Critical

    CVE-2024-46479

    Last Modified: 7 Oct 2025

    Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2024-54999

    Last Modified: 7 Oct 2025

    MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

    Published: 13 Jan 2025
    9.1
    Critical

    CVE-2024-46310

    Last Modified: 15 Apr 2026

    Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

    Published: 13 Jan 2025
    8.4
    High

    CVE-2024-46480

    Last Modified: 3 Oct 2025

    An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2024-57488

    Last Modified: 3 Apr 2025

    Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2024-57487

    Last Modified: 3 Apr 2025

    In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

    Published: 13 Jan 2025
    7.5
    High

    CVE-2025-22963

    Last Modified: 7 Oct 2025

    Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2023-42229

    Last Modified: 17 Apr 2025

    Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.

    Published: 13 Jan 2025
    3.8
    Low

    CVE-2023-42237

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.

    Published: 13 Jan 2025
    8.8
    High

    CVE-2023-42244

    Last Modified: 17 Apr 2025

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.

    Published: 13 Jan 2025
    6.1
    Medium

    CVE-2024-44771

    Last Modified: 15 Apr 2026

    BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.

    Published: 13 Jan 2025
    9.1
    Critical

    CVE-2024-57811

    Last Modified: 15 Apr 2026

    In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0402

    Last Modified: 21 Oct 2025

    A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jan 2025
    6.9
    Medium

    CVE-2025-0401

    Last Modified: 21 Oct 2025

    A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the argument name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jan 2025
    5.1
    Medium

    CVE-2025-0400

    Last Modified: 10 Oct 2025

    A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jan 2025
    5.1
    Medium

    CVE-2025-0399

    Last Modified: 10 Oct 2025

    A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/common/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jan 2025
    1.6
    Low

    CVE-2024-42181

    Last Modified: 16 May 2025

    HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

    Published: 12 Jan 2025
    1.6
    Low

    CVE-2024-42180

    Last Modified: 16 May 2025

    HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

    Published: 12 Jan 2025
    2
    Low

    CVE-2024-42179

    Last Modified: 16 May 2025

    HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.

    Published: 12 Jan 2025
    5.1
    Medium

    CVE-2025-0398

    Last Modified: 15 Apr 2026

    A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /resources/..;/inport/updateInport of the component Backend. The manipulation of the argument remark leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jan 2025
    5.9
    Medium

    CVE-2024-51456

    Last Modified: 28 Mar 2025

    IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.

    Published: 12 Jan 2025
    5.3
    Medium

    CVE-2025-0397

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 12 Jan 2025
    8.5
    High

    CVE-2025-0396

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConnection of the component XPC Service. The manipulation leads to command injection. It is possible to launch the attack on the local host. Upgrading to version 2.11.22 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Jan 2025
    5.4
    Medium

    CVE-2021-29669

    Last Modified: 13 Mar 2025

    IBM Jazz Foundation 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 12 Jan 2025