Latest CVE Feed
-
4.6
MEDIUMCVE-2024-10523
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-38139
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : dataverse- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-45085
IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of servi... Read more
Affected Products : websphere_application_server- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-10035
Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that t... Read more
Affected Products : coslat- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
5.4
MEDIUMCVE-2024-50335
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicio... Read more
Affected Products : suitecrm- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-8541
The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in ... Read more
Affected Products : discount_rules_for_woocommerce- Published: Oct. 16, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-38408
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +460 more products- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-49340
IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : watson_studio_local- Published: Oct. 16, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-51661
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.... Read more
Affected Products : media_library_assistant- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024
-
4.6
MEDIUMCVE-2024-46872
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-49670
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through 1.8.6.... Read more
Affected Products : client_power_tools- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-49673
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Van Abel LaTeX2HTML allows Reflected XSS.This issue affects LaTeX2HTML: from n/a through 2.5.4.... Read more
Affected Products : latex2html- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-49692
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AffiliateX allows Stored XSS.This issue affects AffiliateX: from n/a through 1.2.9.... Read more
Affected Products : affiliatex- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-50439
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.14.... Read more
Affected Products : astra_widgets- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50438
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a before 5.0.0.... Read more
Affected Products : church_admin- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
5.9
MEDIUMCVE-2024-49679
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPKoi WPKoi Templates for Elementor allows Stored XSS.This issue affects WPKoi Templates for Elementor: from n/a through 3.1.0.... Read more
Affected Products : wpkoi_templates_for_elementor- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
4.7
MEDIUMCVE-2024-50135
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() should avoid racing aga... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-49702
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in myCRED myCred Elementor allows Stored XSS.This issue affects myCred Elementor: from n/a through 1.2.6.... Read more
Affected Products : mycred_elementor- Published: Oct. 24, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-22066
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.... Read more
- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50136
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt at eswitch enabling might trigger warnings of the sort: [ 682.589148] --... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024