CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-50824

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50825

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50826

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50827

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50828

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50830

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50831

    Last Modified: 18 Nov 2024

    A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50832

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

    Published: 14 Nov 2024
    9.8
    Critical

    CVE-2024-50833

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50834

    Last Modified: 18 Nov 2024

    A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.

    Published: 14 Nov 2024
    4.8
    Medium

    CVE-2024-50836

    Last Modified: 18 Nov 2024

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and lastname parameters.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50837

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and username parameters.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50838

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the d and pi parameters.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50839

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50840

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50842

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter.

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-50843

    Last Modified: 27 Mar 2025

    A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive files and directories via /loginsystem/assets.

    Published: 14 Nov 2024
    4.7
    Medium

    CVE-2024-51156

    Last Modified: 18 Apr 2025

    07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

    Published: 14 Nov 2024
    5.5
    Medium

    CVE-2024-52613

    Last Modified: 20 Nov 2024

    A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafted MOV video file.

    Published: 14 Nov 2024
    —
    Unknown

    CVE-2024-43811

    Last Modified: 6 Feb 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024. Notes: none.

    Published: 13 Nov 2024
    5.1
    Medium

    CVE-2024-36284

    Last Modified: 15 Apr 2026

    Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Nov 2024
    7.3
    High

    CVE-2024-39766

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    7.7
    High

    CVE-2024-28028

    Last Modified: 15 Apr 2026

    Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Nov 2024
    8.6
    High

    CVE-2024-39368

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-34165

    Last Modified: 15 Apr 2026

    Uncontrolled search path in some Intel(R) oneAPI DPC++/C++ Compiler before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-34022

    Last Modified: 15 Apr 2026

    Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    7
    High

    CVE-2024-32483

    Last Modified: 2 Sept 2025

    Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-36294

    Last Modified: 4 Feb 2025

    Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-36488

    Last Modified: 4 Feb 2025

    Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-37025

    Last Modified: 15 Apr 2026

    Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    2
    Low

    CVE-2024-38660

    Last Modified: 15 Apr 2026

    Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    7.3
    High

    CVE-2024-36242

    Last Modified: 15 Apr 2026

    Protection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-38383

    Last Modified: 4 Feb 2025

    Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-38668

    Last Modified: 4 Feb 2025

    Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-38387

    Last Modified: 15 Apr 2026

    Uncontrolled search path in the Intel(R) Graphics Driver installers for versions 15.40 and 15.45 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    6.9
    Medium

    CVE-2024-21799

    Last Modified: 15 Apr 2026

    Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.8
    Medium

    CVE-2024-36275

    Last Modified: 15 Apr 2026

    NULL pointer dereference in some Intel(R) Optane(TM) PMem Management software versions before CR_MGMT_02.00.00.4040, CR_MGMT_03.00.00.0499 may allow a authenticated user to potentially enable denial of service via local access.

    Published: 13 Nov 2024
    2
    Low

    CVE-2024-34776

    Last Modified: 15 Apr 2026

    Out-of-bounds write in some Intel(R) SGX SDK software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.2
    Medium

    CVE-2024-37027

    Last Modified: 2 Sept 2025

    Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-36245

    Last Modified: 2 Sept 2025

    Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-34167

    Last Modified: 15 Apr 2026

    Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    7.1
    High

    CVE-2024-36282

    Last Modified: 15 Apr 2026

    Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    7.1
    High

    CVE-2024-36482

    Last Modified: 4 Feb 2025

    Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-36276

    Last Modified: 4 Feb 2025

    Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-36253

    Last Modified: 4 Feb 2025

    Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-35201

    Last Modified: 4 Feb 2025

    Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.

    Published: 13 Nov 2024
    8.2
    High

    CVE-2024-31074

    Last Modified: 15 Apr 2026

    Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

    Published: 13 Nov 2024
    8.2
    High

    CVE-2024-28885

    Last Modified: 15 Apr 2026

    Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

    Published: 13 Nov 2024
    8.2
    High

    CVE-2024-33617

    Last Modified: 15 Apr 2026

    Insufficient control flow management in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network access.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-37024

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some ACAT software maintained by Intel(R) for Windows before version 3.11.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2024