Latest CVE Feed
-
2.2
LOWCVE-2024-51755
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the sec... Read more
Affected Products : twig- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
9.3
CRITICALCVE-2024-51990
jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable t... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2019-20460
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request is from a legitimate source. In addition, CSRF attacks can be used to send text... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-46960
The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
5.4
MEDIUMCVE-2024-51987
Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's access token after a token refresh occurs. This occ... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
0.0
NACVE-2024-50199
In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: skip HugeTLB pages for unuse_vma I got a bad pud error and lost a 1GB HugeTLB when calling swapoff. The problem can be reproduced by the following steps: 1. Allocate an ... Read more
Affected Products : linux_kernel- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-50591
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by comm... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-8424
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. This issue affects EPDR: before 8.00.23.0000; Panda AD360: before 8.00.23.000... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-10621
The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping on user supplie... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
8.6
HIGHCVE-2024-51998
changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This issue only affects instances with a webdriver enabled, ... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
7.8
HIGHCVE-2024-50590
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory of Elefant is "C:... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-47072
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input strea... Read more
- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2023-1973
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.... Read more
Affected Products : undertow- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.7
HIGHCVE-2024-10975
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed... Read more
Affected Products : nomad- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.0
HIGHCVE-2024-10203
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.... Read more
Affected Products : manageengine_endpoint_central- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-51428
An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-36063
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivi... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-48290
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-50589
An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2020-8007
The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip.... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024