Latest CVE Feed
-
9.8
CRITICALCVE-2024-47636
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-43929
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-43928
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47302
Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0.... Read more
Affected Products : fluent_support- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47308
Missing Authorization vulnerability in Templately allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Templately: from n/a through 3.1.2.... Read more
Affected Products : templately- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47311
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.... Read more
Affected Products : wheel_of_life- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47314
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.8.... Read more
Affected Products : sunshine_photo_cart- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47317
Missing Authorization vulnerability in WP Quads Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads: from n/a th... Read more
Affected Products : ads- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47318
Missing Authorization vulnerability in Magazine3 PWA for WP & AMP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PWA for WP & AMP: from n/a through 1.7.72.... Read more
Affected Products : pwa_for_wp_\&_amp- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47321
Missing Authorization vulnerability in Fahad Mahmood WP Datepicker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Datepicker: from n/a through 2.1.1.... Read more
Affected Products : wp_datepicker- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47358
Missing Authorization vulnerability in Popup Maker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Popup Maker: from n/a through 1.19.2.... Read more
Affected Products : popup_maker- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-47359
Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Depicter Slider: from n/a through 3.2.2.... Read more
Affected Products : depicter- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
5.5
MEDIUMCVE-2024-50095
In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Improve handling of timed out WRs of mad agent Current timeout handler of mad agent acquires/releases mad_agent_priv lock for every timed out WRs. This causes heavy locking co... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47361
Missing Authorization vulnerability in WPVibes Elementor Addon Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Addon Elements: from n/a through 1.13.6.... Read more
Affected Products : elementor_addon_elements- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
7.5
HIGHCVE-2024-45397
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect... Read more
Affected Products : h2o- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
7.5
HIGHCVE-2024-45396
Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vulnerability is add... Read more
Affected Products : quicly- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2024-25622
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers handler allows users to modify the response headers being sent by h2o. The configuration file of h2o has scopes, and the inner scopes ... Read more
Affected Products : h2o- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-45402
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may attempt to free ... Read more
- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
7.5
HIGHCVE-2024-45403
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due to an assertion failure. The crash can be exploited by an attacker to mount ... Read more
Affected Products : h2o- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024
-
9.3
CRITICALCVE-2024-47830
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. ... Read more
Affected Products : plane- Published: Oct. 11, 2024
- Modified: Nov. 12, 2024