Latest CVE Feed
-
9.3
CRITICALCVE-2024-27954
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-1542
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating syste... Read more
Affected Products : sf220-24p_firmware sf220-48_firmware sf220-48p_firmware sg220-26_firmware sg220-26p_firmware sg220-28mp_firmware sg220-50_firmware sg220-50p_firmware sf220-24_firmware sf220-24p +8 more products- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-2882
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA syst... Read more
Affected Products : pnpscada- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-38368
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to d... Read more
Affected Products : trunk.cocoapods.org- Published: Jul. 01, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-28580
Medium by Adobe version 2.4.5.331 (and earlier) is affected by a buffer overflow vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. ... Read more
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-4976
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.... Read more
Affected Products :- Published: Jul. 17, 2024
- Modified: Apr. 10, 2025
-
9.3
HIGHCVE-2021-24016
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsa... Read more
Affected Products : fortimanager- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-42348
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.... Read more
Affected Products : fogproject- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024
-
9.3
CRITICALCVE-2024-6915
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.... Read more
Affected Products : artifactory- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
9.3
HIGHCVE-2011-4126
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.... Read more
Affected Products : calibre- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-3886
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to execute arbitrary code with ... Read more
- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-42500
HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.... Read more
Affected Products :- Published: Sep. 09, 2024
- Modified: Sep. 10, 2024
-
9.3
CRITICALCVE-2024-47350
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Ajax Search allows SQL Injection.This issue affects YITH WooCommerce Ajax Search: from n/a through 2.8.0.... Read more
Affected Products : yith_woocommerce_ajax_search- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
9.3
CRITICALCVE-2023-52952
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.3
CRITICALCVE-2024-47562
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, low... Read more
Affected Products : sinec_security_monitor- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
9.3
CRITICALCVE-2024-47830
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. ... Read more
Affected Products : plane- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
9.3
CRITICALCVE-2024-46538
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.... Read more
Affected Products : pfsense- Published: Oct. 22, 2024
- Modified: Oct. 30, 2024
-
9.3
CRITICALCVE-2024-20412
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to th... Read more
Affected Products : firepower_threat_defense firepower_1010 firepower_1120 firepower_1140 firepower_1150 firepower_2110 firepower_2120 firepower_2130 firepower_2140 firepower_1000 +12 more products- Published: Oct. 23, 2024
- Modified: Nov. 05, 2024
-
9.3
CRITICALCVE-2024-48548
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a valid serial number... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
9.3
HIGHCVE-2021-39701
In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foreground without notification or permission due to improper input validation. This could lead to local escalation of privilege with no additi... Read more
Affected Products : android- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024