Latest CVE Feed
-
5.3
MEDIUMCVE-2024-49395
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
6.4
MEDIUMCVE-2024-10538
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output e... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-11054
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload... Read more
Affected Products : simple_music_cloud_community_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-50235
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we also need to clear out the pointer since the same wdev/netdev may get re-regi... Read more
Affected Products : linux_kernel- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
7.0
HIGHCVE-2024-50234
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlegacy: Clear stale interrupts before resuming device iwl4965 fails upon resume from hibernation on my laptop. The reason seems to be a stale interrupt which isn't being cleared... Read more
Affected Products : linux_kernel- Published: Nov. 09, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51576
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZA AMP Img Shortcode allows Stored XSS.This issue affects AMP Img Shortcode: from n/a through 1.0.1.... Read more
Affected Products : amp_img_shortcode- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51578
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Luca Paggetti 3D Presentation allows Stored XSS.This issue affects 3D Presentation: from n/a through 1.0.... Read more
Affected Products : 3d_presentation- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51577
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Camunda Services GmbH bpmn.Io allows Stored XSS.This issue affects bpmn.Io: from n/a through 1.0.... Read more
Affected Products : bpmn.io- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51584
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Anas Edreesi Marquee Elementor with Posts allows DOM-Based XSS.This issue affects Marquee Elementor with Posts: from n/a through 1.2.0.... Read more
Affected Products : marquee_elementor_with_posts- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51583
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KentoThemes Kento Ads Rotator allows Stored XSS.This issue affects Kento Ads Rotator: from n/a through 1.3.... Read more
Affected Products : kento_ads_rotator- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
5.5
MEDIUMCVE-2024-44197
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious app may be able to cause a denial-of-service.... Read more
Affected Products : macos- Published: Oct. 28, 2024
- Modified: Nov. 14, 2024
-
7.5
HIGHCVE-2024-44196
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: Oct. 28, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-46951
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.4
HIGHCVE-2024-46952
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-46953
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.1
MEDIUMCVE-2024-47648
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in EventPrime Events EventPrime.This issue affects EventPrime: from n/a through 4.0.4.5.... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 14, 2024
-
5.5
MEDIUMCVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.2
HIGHCVE-2024-47604
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.... Read more
Affected Products : nugetgallery- Published: Oct. 01, 2024
- Modified: Nov. 13, 2024
-
8.7
HIGHCVE-2024-50310
A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not properly handle authorization. This could allow an unauthenticated remote attacker to gain access to the filesy... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
7.3
HIGHCVE-2024-47942
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the sy... Read more
Affected Products : solid_edge_se2024- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024