Latest CVE Feed
-
6.8
MEDIUMCVE-2024-34887
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.... Read more
Affected Products : bitrix24- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51329
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.... Read more
Affected Products : agile-board- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-10097
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. This makes it po... Read more
Affected Products : loginizer- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-49368
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 ... Read more
Affected Products : nginx_ui- Published: Oct. 21, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51115
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-42509
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-20371
A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device. This vulnerabili... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
8.7
HIGHCVE-2024-51735
Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be executed on the server. When using a workflow that contains the summary modu... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
6.8
MEDIUMCVE-2024-47464
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operat... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
4.8
MEDIUMCVE-2024-20533
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (X... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-48746
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
7.2
HIGHCVE-2024-47463
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote comm... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-20418
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with r... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
6.7
MEDIUMCVE-2023-29122
Under certain conditions, access to service libraries is granted to account they should not have access to.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-48312
WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
2.1
LOWCVE-2024-51753
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled. Thi... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
2.1
LOWCVE-2024-51752
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled.... Read more
Affected Products : authkit- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-20445
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is ... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-10081
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints other ... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024
-
4.8
MEDIUMCVE-2024-20534
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (X... Read more
Affected Products :- Published: Nov. 06, 2024
- Modified: Nov. 06, 2024