Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2024-50136

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt at eswitch enabling might trigger warnings of the sort: [ 682.589148] --... Read more

    Affected Products : linux_kernel
    • Published: Nov. 05, 2024
    • Modified: Nov. 08, 2024
  • 6.1

    MEDIUM
    CVE-2024-7784

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' ... Read more

    Affected Products : axis_os
    • Published: Sep. 10, 2024
    • Modified: Nov. 08, 2024
  • 6.8

    MEDIUM
    CVE-2024-6979

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires comp... Read more

    Affected Products : axis_os
    • Published: Sep. 10, 2024
    • Modified: Nov. 08, 2024
  • 4.3

    MEDIUM
    CVE-2024-0067

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS ver... Read more

    Affected Products : axis_os
    • Published: Sep. 10, 2024
    • Modified: Nov. 08, 2024
  • 7.8

    HIGH
    CVE-2024-50129

    In the Linux kernel, the following vulnerability has been resolved: net: pse-pd: Fix out of bound for loop Adjust the loop limit to prevent out-of-bounds access when iterating over PI structures. The loop should not reach the index pcdev->nr_lines since... Read more

    Affected Products : linux_kernel
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 5.5

    MEDIUM
    CVE-2024-50132

    In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling When creating a trace_probe we would set nr_args prior to truncating the arguments to MAX_TRACE_ARGS. However, we would only initialize... Read more

    Affected Products : linux_kernel
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 5.5

    MEDIUM
    CVE-2024-50133

    In the Linux kernel, the following vulnerability has been resolved: LoongArch: Don't crash in stack_top() for tasks without vDSO Not all tasks have a vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will de... Read more

    Affected Products : linux_kernel
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 5.9

    MEDIUM
    CVE-2024-50411

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.7.1.... Read more

    Affected Products : wp_abstracts
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 7.1

    HIGH
    CVE-2024-49642

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rafasashi Todo Custom Field allows Reflected XSS.This issue affects Todo Custom Field: from n/a through 3.0.4.... Read more

    Affected Products : todo_custom_field
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 6.4

    MEDIUM
    CVE-2024-9443

    The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more

    Affected Products : framework
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 9.8

    CRITICAL
    CVE-2024-51358

    An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.... Read more

    Affected Products :
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 5.3

    MEDIUM
    CVE-2024-47855

    util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.... Read more

    Affected Products :
    • Published: Oct. 04, 2024
    • Modified: Nov. 07, 2024
  • 5.5

    MEDIUM
    CVE-2024-51513

    Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.... Read more

    Affected Products : harmonyos
    • Published: Nov. 05, 2024
    • Modified: Nov. 07, 2024
  • 6.5

    MEDIUM
    CVE-2024-50410

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.4.... Read more

    Affected Products : namaste\!_lms
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 6.5

    MEDIUM
    CVE-2024-50409

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.... Read more

    Affected Products : namaste\!_lms
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 7.1

    HIGH
    CVE-2024-50407

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Reflected XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.... Read more

    Affected Products : namaste\!_lms
    • Published: Oct. 29, 2024
    • Modified: Nov. 07, 2024
  • 7.5

    HIGH
    CVE-2024-33068

    Transient DOS while parsing fragments of MBSSID IE from beacon frame.... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 07, 2024
  • 7.5

    HIGH
    CVE-2024-38403

    Transient DOS while parsing BTM ML IE when per STA profile is not included.... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 07, 2024
  • 7.5

    HIGH
    CVE-2024-38405

    Transient DOS while processing the CU information from RNR IE.... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 07, 2024
  • 7.5

    HIGH
    CVE-2024-23385

    Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.... Read more

    • Published: Nov. 04, 2024
    • Modified: Nov. 07, 2024
Showing 20 of 291205 Results