NA - CVE-2024-11846 - The does not sanitise and escape a parameter...
The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
NA - CVE-2025-0168 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The manipulation of the argument...
High - CVE-2024-12838 - The passwordless login mechanism in CGFIDO from...
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted...
High - CVE-2024-12839 - The login mechanism via device authentication...
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program...
High - CVE-2024-13040 - The QOCA aim from Quanta Computer has an...
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access...
High - CVE-2024-45497 - A flaw was found in the OpenShift build...
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the...
NA - CVE-2024-11972 - The Hunk Companion WordPress plugin before...
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress...
NA - CVE-2024-13067 - A vulnerability was found in CodeAstro Online...
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All...
NA - CVE-2024-49422 - Protection Mechanism Failure in bootloader...
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for...