Latest CVE Feed
-
5.5
MEDIUMCVE-2024-50136
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt at eswitch enabling might trigger warnings of the sort: [ 682.589148] --... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-7784
During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' ... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
6.8
MEDIUMCVE-2024-6979
Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires comp... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-0067
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS ver... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-50129
In the Linux kernel, the following vulnerability has been resolved: net: pse-pd: Fix out of bound for loop Adjust the loop limit to prevent out-of-bounds access when iterating over PI structures. The loop should not reach the index pcdev->nr_lines since... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.5
MEDIUMCVE-2024-50132
In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling When creating a trace_probe we would set nr_args prior to truncating the arguments to MAX_TRACE_ARGS. However, we would only initialize... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.5
MEDIUMCVE-2024-50133
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Don't crash in stack_top() for tasks without vDSO Not all tasks have a vDSO mapped, for example kthreads never do. If such a task ever ends up calling stack_top(), it will de... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.9
MEDIUMCVE-2024-50411
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.7.1.... Read more
Affected Products : wp_abstracts- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
7.1
HIGHCVE-2024-49642
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rafasashi Todo Custom Field allows Reflected XSS.This issue affects Todo Custom Field: from n/a through 3.0.4.... Read more
Affected Products : todo_custom_field- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
6.4
MEDIUMCVE-2024-9443
The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
Affected Products : framework- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
9.8
CRITICALCVE-2024-51358
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
5.3
MEDIUMCVE-2024-47855
util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.... Read more
Affected Products :- Published: Oct. 04, 2024
- Modified: Nov. 07, 2024
-
5.5
MEDIUMCVE-2024-51513
Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.... Read more
Affected Products : harmonyos- Published: Nov. 05, 2024
- Modified: Nov. 07, 2024
-
6.5
MEDIUMCVE-2024-50410
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.4.... Read more
Affected Products : namaste\!_lms- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
6.5
MEDIUMCVE-2024-50409
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.... Read more
Affected Products : namaste\!_lms- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
7.1
HIGHCVE-2024-50407
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Reflected XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.... Read more
Affected Products : namaste\!_lms- Published: Oct. 29, 2024
- Modified: Nov. 07, 2024
-
7.5
HIGHCVE-2024-33068
Transient DOS while parsing fragments of MBSSID IE from beacon frame.... Read more
Affected Products : qam8295p_firmware qca6391_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6155p_firmware sa8155p_firmware sa8195p_firmware sa8295p_firmware wcd9341_firmware +236 more products- Published: Nov. 04, 2024
- Modified: Nov. 07, 2024
-
7.5
HIGHCVE-2024-38403
Transient DOS while parsing BTM ML IE when per STA profile is not included.... Read more
Affected Products : qca6574au_firmware qca6595au_firmware qca6696_firmware wcd9380_firmware wcd9385_firmware wcn3980_firmware wsa8830_firmware wsa8835_firmware ar8035_firmware qca6554a_firmware +146 more products- Published: Nov. 04, 2024
- Modified: Nov. 07, 2024
-
7.5
HIGHCVE-2024-38405
Transient DOS while processing the CU information from RNR IE.... Read more
Affected Products : qam8295p_firmware qca6391_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6155p_firmware sa8155p_firmware sa8195p_firmware sa8295p_firmware wcd9380_firmware +190 more products- Published: Nov. 04, 2024
- Modified: Nov. 07, 2024
-
7.5
HIGHCVE-2024-23385
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.... Read more
Affected Products : qca6574au_firmware qca6595au_firmware qca6696_firmware wcd9380_firmware wcd9385_firmware wcn3980_firmware wcn3988_firmware wsa8810_firmware wsa8815_firmware wsa8830_firmware +179 more products- Published: Nov. 04, 2024
- Modified: Nov. 07, 2024