Latest CVE Feed
-
5.9
MEDIUMCVE-2024-41738
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.... Read more
Affected Products : txseries_for_multiplatforms- Published: Nov. 01, 2024
- Modified: Nov. 14, 2024
-
8.8
HIGHCVE-2024-25431
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.... Read more
Affected Products : webassembly_micro_runtime- Published: Nov. 08, 2024
- Modified: Nov. 14, 2024
-
5.3
MEDIUMCVE-2024-41741
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system.... Read more
Affected Products : txseries_for_multiplatforms- Published: Nov. 01, 2024
- Modified: Nov. 14, 2024
-
8.8
HIGHCVE-2024-50634
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability is not limited to privilege escalation but also affects all functions that require authenticat... Read more
Affected Products : watcharr- Published: Nov. 08, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-46956
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.5
HIGHCVE-2024-40592
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with... Read more
Affected Products : forticlient- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
6.1
MEDIUMCVE-2024-41745
IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : cics_tx- Published: Nov. 01, 2024
- Modified: Nov. 14, 2024
-
5.9
MEDIUMCVE-2024-46635
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Nov. 14, 2024
-
8.8
HIGHCVE-2024-36513
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.... Read more
Affected Products : forticlient- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
4.4
MEDIUMCVE-2024-36509
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticat... Read more
Affected Products : fortiweb- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-36507
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.... Read more
Affected Products : forticlient- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51597
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeShark ThemeShark Templates & Widgets for Elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/... Read more
Affected Products : themeshark_templates_\&_widgets_for_elementor- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51589
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpcirqle Bigmart Elements allows DOM-Based XSS.This issue affects Bigmart Elements: from n/a through 1.0.3.... Read more
Affected Products : bigmart_elements- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51588
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themehat Super Addons for Elementor allows DOM-Based XSS.This issue affects Super Addons for Elementor: from n/a through 1.0.... Read more
Affected Products : super_addons_for_elementor- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51587
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Softfirm Definitive Addons for Elementor allows Stored XSS.This issue affects Definitive Addons for Elementor: from n/a through 1.5.16.... Read more
Affected Products : definitive_addons_for_elementor- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-52351
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boston University (IS&T) BU Slideshow allows Stored XSS.This issue affects BU Slideshow: from n/a through 2.3.10.... Read more
Affected Products : bu_slideshow- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-52350
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CRM 2go allows DOM-Based XSS.This issue affects CRM 2go: from n/a through 1.0.... Read more
Affected Products : crm2go- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024
-
8.1
HIGHCVE-2024-51484
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows an attacker to exploit CSR... Read more
Affected Products : ampache- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024
-
9.0
CRITICALCVE-2024-51490
Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized, allowing for the input o... Read more
Affected Products : ampache- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024
-
5.4
MEDIUMCVE-2024-51488
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to forge CSRF attacks, allowi... Read more
Affected Products : ampache- Published: Nov. 11, 2024
- Modified: Nov. 14, 2024