Latest CVE Feed
-
7.1
HIGHCVE-2024-49220
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.... Read more
Affected Products : cookie_scanner- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49229
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.... Read more
Affected Products : better_author_bio- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-31880
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51362
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network ... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-51240
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51132
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.7
HIGHCVE-2024-42018
An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to t... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-39339
A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosure, leaking sensitive details such as diagnostic log traces, system logs, he... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49237
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through 5.1.... Read more
Affected Products : ahmeti_wp_timeline- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
5.9
MEDIUMCVE-2024-51685
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Accordion title for Elementor allows Stored XSS.This issue affects Accordion title for Elementor: from n/a through 1.2.1.... Read more
Affected Products : accordion_title_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-48809
An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifically the DeleteWatcher function.... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51136
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.... Read more
Affected Products : openimaj- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-34882
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.... Read more
Affected Products : bitrix24- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-34883
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.... Read more
Affected Products : bitrix24- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-34887
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.... Read more
Affected Products : bitrix24- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51329
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.... Read more
Affected Products : agile-board- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-10097
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it po... Read more
Affected Products : loginizer- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-49368
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 ... Read more
Affected Products : nginx_ui- Published: Oct. 21, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-47464
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operat... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-20445
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is ... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024