Latest CVE Feed
-
7.1
HIGHCVE-2024-46854
In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending packets under 60 bytes, up to three bytes of the buffer following the data may be leaked. Avoid this by extending all packets to ETH_ZLEN... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-46853
In the Linux kernel, the following vulnerability has been resolved: spi: nxp-fspi: fix the KASAN report out-of-bounds bug Change the memcpy length to fix the out-of-bounds issue when writing the data that is not 4 byte aligned to TX FIFO. To reproduce ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-46849
In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: axg-card: fix 'use-after-free' Buffer 'card->dai_link' is reallocated in 'meson_card_reallocate_links()', so move 'pad' pointer initialization after this function when memo... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-44988
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] arra... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-44931
In the Linux kernel, the following vulnerability has been resolved: gpio: prevent potential speculation leaks in gpio_device_get_desc() Userspace may trigger a speculative read of an address outside the gpio descriptor array. Users can do that by callin... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2023-52913
In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential context UAFs gem_context_register() makes the context visible to userspace, and which point a separate thread can trigger the I915_GEM_CONTEXT_DESTROY ioctl. So ... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2022-48938
In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like 0xFFF0 and a reasonable length for a fragment. In the sanity check as formulated now, this wil... Read more
Affected Products : linux_kernel- Published: Aug. 22, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2022-48910
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ensure we call ipv6_mc_down() at most once There are two reasons for addrconf_notify() to be called with NETDEV_DOWN: either the network device is actually going down, or IPv... Read more
Affected Products : linux_kernel- Published: Aug. 22, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2023-29126
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.0
CRITICALCVE-2023-29125
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29121
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29120
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29119
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.6
CRITICALCVE-2023-29118
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2023-29117
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2023-29116
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2023-29115
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-9178
The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for ... Read more
Affected Products : xt_floating_cart_for_woocommerce- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-9657
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to i... Read more
Affected Products : element_pack- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.4
MEDIUMCVE-2024-9867
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and inc... Read more
Affected Products : element_pack- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024