Latest CVE Feed
-
4.8
MEDIUMCVE-2024-23387
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is loggi... Read more
Affected Products : fusionpbx- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23348
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
5.5
MEDIUMCVE-2024-23215
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to access user-sensitive data.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23214
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3. Processing maliciously crafted web content may lead to arbitrary code executi... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2024-23212
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to execute ar... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23209
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.... Read more
Affected Products : macos- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2024-23204
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2024-23203
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-23182
Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2024-22956
swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838... Read more
Affected Products : swftools- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2024-22915
A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.... Read more
Affected Products : swftools- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2024-22913
A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.... Read more
Affected Products : swftools- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-22663
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-22638
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.... Read more
Affected Products : livesite- Published: Jan. 25, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-22636
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.... Read more
Affected Products : pluxml- Published: Jan. 25, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2024-22497
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.... Read more
Affected Products : jfinalcms- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
6.5
MEDIUMCVE-2024-0814
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-0812
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-0808
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)... Read more
- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2024-0758
MolecularFaces before 0.3.0 is vulnerable to cross site scripting. A remote attacker can execute arbitrary JavaScript in the context of a victim browser via crafted molfiles. ... Read more
Affected Products : molecularfaces- Published: Jan. 19, 2024
- Modified: May. 30, 2025