Latest CVE Feed
-
6.1
MEDIUMCVE-2024-8541
The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in ... Read more
Affected Products : discount_rules_for_woocommerce- Published: Oct. 16, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-38408
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +460 more products- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-49340
IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : watson_studio_local- Published: Oct. 16, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-51661
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.... Read more
Affected Products : media_library_assistant- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
4.6
MEDIUMCVE-2024-46872
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-49670
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through 1.8.6.... Read more
Affected Products : client_power_tools- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-49673
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Van Abel LaTeX2HTML allows Reflected XSS.This issue affects LaTeX2HTML: from n/a through 2.5.4.... Read more
Affected Products : latex2html- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-49692
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AffiliateX allows Stored XSS.This issue affects AffiliateX: from n/a through 1.2.9.... Read more
Affected Products : affiliatex- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-50439
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.14.... Read more
Affected Products : astra_widgets- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50438
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a before 5.0.0.... Read more
Affected Products : church_admin- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
5.9
MEDIUMCVE-2024-49679
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPKoi WPKoi Templates for Elementor allows Stored XSS.This issue affects WPKoi Templates for Elementor: from n/a through 3.1.0.... Read more
Affected Products : wpkoi_templates_for_elementor- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
4.7
MEDIUMCVE-2024-50135
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() should avoid racing aga... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-49702
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in myCRED myCred Elementor allows Stored XSS.This issue affects myCred Elementor: from n/a through 1.2.6.... Read more
Affected Products : mycred_elementor- Published: Oct. 24, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-22066
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50136
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt at eswitch enabling might trigger warnings of the sort: [ 682.589148] --... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-7784
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' ... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
6.8
MEDIUMCVE-2024-6979
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires comp... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-0067
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS ver... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-50129
In the Linux kernel, the following vulnerability has been resolved: net: pse-pd: Fix out of bound for loop Adjust the loop limit to prevent out-of-bounds access when iterating over PI structures. The loop should not reach the index pcdev->nr_lines since... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.5
MEDIUMCVE-2024-50132
In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling When creating a trace_probe we would set nr_args prior to truncating the arguments to MAX_TRACE_ARGS. However, we would only initialize... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024