Latest CVE Feed
-
9.8
CRITICALCVE-2024-9486
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9484
An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9483
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
8.1
HIGHCVE-2024-9594
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. T... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9482
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9481
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43980
Missing Authorization vulnerability in CozyThemes Fota WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fota WP: from n/a through 1.4.1.... Read more
Affected Products : fotawp- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43979
Missing Authorization vulnerability in CozyThemes Blockbooster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockbooster: from n/a through 1.0.10.... Read more
Affected Products : blockbooster- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43974
Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2.... Read more
Affected Products : revivenews- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43973
Missing Authorization vulnerability in AyeCode Ltd GetPaid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through 2.8.11.... Read more
Affected Products : getpaid- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43968
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.... Read more
Affected Products : newspack- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43962
Missing Authorization vulnerability in LWS LWS Affiliation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LWS Affiliation: from n/a through 2.3.4.... Read more
Affected Products : affiliation- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43956
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.... Read more
Affected Products : memberpress- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
6.9
MEDIUMCVE-2024-52043
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.... Read more
Affected Products : humhub- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
8.1
HIGHCVE-2024-9946
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by ... Read more
Affected Products : super_socializer- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50113
In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix invalid port index for parent device In a commit 24b7f8e5cd65 ("firewire: core: use helper functions for self ID sequence"), the enumeration over self ID sequence wa... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-50112
In the Linux kernel, the following vulnerability has been resolved: x86/lam: Disable ADDRESS_MASKING in most cases Linear Address Masking (LAM) has a weakness related to transient execution as described in the SLAM paper[1]. Unless Linear Address Space ... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-50446
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in FuturioWP Futurio Extra allows Stored XSS.This issue affects Futurio Extra: from n/a through 2.0.11.... Read more
Affected Products : futurio_extra- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-50445
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Merkulove Selection Lite allows Stored XSS.This issue affects Selection Lite: from n/a through 1.13.... Read more
Affected Products : selection_lite- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
7.4
HIGHCVE-2024-50441
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.15.... Read more
Affected Products : cozy_blocks- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024