Latest CVE Feed
-
5.5
MEDIUMCVE-2024-50110
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping During fuzz testing, the following issue was discovered: BUG: KMSAN: kernel-infoleak in _copy_to_iter+0x598/0x2a30 _copy_to_iter+0x5... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-44020
Missing Authorization vulnerability in Prasad Kirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS allows . This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through 1.2.6.... Read more
Affected Products : wp_free_ssl- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-8499
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitiz... Read more
Affected Products : checkout_field_editor- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-8184
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors ... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-9486
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9484
An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9483
A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
8.1
HIGHCVE-2024-9594
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. T... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9482
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-9481
An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file to crash the application during file processing.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43980
Missing Authorization vulnerability in CozyThemes Fota WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fota WP: from n/a through 1.4.1.... Read more
Affected Products : fotawp- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43979
Missing Authorization vulnerability in CozyThemes Blockbooster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockbooster: from n/a through 1.0.10.... Read more
Affected Products : blockbooster- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43974
Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2.... Read more
Affected Products : revivenews- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43973
Missing Authorization vulnerability in AyeCode Ltd GetPaid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through 2.8.11.... Read more
Affected Products : getpaid- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43968
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.... Read more
Affected Products : newspack- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-43962
Missing Authorization vulnerability in LWS LWS Affiliation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LWS Affiliation: from n/a through 2.3.4.... Read more
Affected Products : affiliation- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-43956
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.... Read more
Affected Products : memberpress- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
6.9
MEDIUMCVE-2024-52043
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released HumHub versions: through 1.16.2.... Read more
Affected Products : humhub- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
8.1
HIGHCVE-2024-9946
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by ... Read more
Affected Products : super_socializer- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50113
In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix invalid port index for parent device In a commit 24b7f8e5cd65 ("firewire: core: use helper functions for self ID sequence"), the enumeration over self ID sequence wa... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024