Latest CVE Feed
-
5.5
MEDIUMCVE-2024-23848
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-23771
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.... Read more
Affected Products : darkhttpd- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
5.5
MEDIUMCVE-2024-23770
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.... Read more
Affected Products : darkhttpd- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23768
Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can access these folders, files, and datasets. To be successful, the user must have access to the sour... Read more
Affected Products : dremio- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-23752
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English lang... Read more
Affected Products : pandasai- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-23730
The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.... Read more
Affected Products : llamahub- Published: Jan. 21, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23726
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by us... Read more
- Published: Jan. 21, 2024
- Modified: May. 30, 2025
-
6.1
MEDIUMCVE-2024-23725
Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.... Read more
Affected Products : ghost- Published: Jan. 21, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23689
Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via cl... Read more
Affected Products : java_libraries- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
5.3
MEDIUMCVE-2024-23685
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types. ... Read more
Affected Products : mod-remote-storage- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-23679
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes. ... Read more
Affected Products : xp- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
4.8
MEDIUMCVE-2024-23387
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is loggi... Read more
Affected Products : fusionpbx- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23348
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
5.5
MEDIUMCVE-2024-23215
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An app may be able to access user-sensitive data.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23214
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3. Processing maliciously crafted web content may lead to arbitrary code executi... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.8
HIGHCVE-2024-23212
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, macOS Ventura 13.6.4, macOS Monterey 12.7.3. An app may be able to execute ar... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-23209
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.... Read more
Affected Products : macos- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2024-23204
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2024-23203
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-23182
Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: May. 30, 2025