Latest CVE Feed
-
7.1
HIGHCVE-2024-7295
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.... Read more
Affected Products : telerik_report_server- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-52876
Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.... Read more
Affected Products :- Published: Nov. 17, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2015-20111
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, r... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
9.0
CRITICALCVE-2024-52300
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the ... Read more
Affected Products : pdf_viewer_macro- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-52299
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the ... Read more
Affected Products : pdf_viewer_macro- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-52298
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate my view right" feature as long as the attacker can view a page whose last author has access to the att... Read more
Affected Products : pdf_viewer_macro- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
8.1
HIGHCVE-2024-11073
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation of the argument id leads to improper authorization. It is ... Read more
Affected Products : hospital_management_system- Published: Nov. 11, 2024
- Modified: Nov. 18, 2024
-
5.5
MEDIUMCVE-2024-42677
An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component... Read more
Affected Products : enterprise_resource_management_system- Published: Aug. 15, 2024
- Modified: Nov. 18, 2024
-
4.6
MEDIUMCVE-2024-23169
The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-3334
A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby comprom... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
3.5
LOWCVE-2024-52507
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextclou... Read more
Affected Products : notes- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
6.7
MEDIUMCVE-2021-34752
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device. This vu... Read more
Affected Products : firepower_threat_defense- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
8.1
HIGHCVE-2022-20649
A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container. This vulner... Read more
Affected Products : redundancy_configuration_manager- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
4.1
MEDIUMCVE-2024-52514
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwa... Read more
Affected Products : notes- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
8.8
HIGHCVE-2022-20655
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affect... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2024-24450
Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
5.8
MEDIUMCVE-2021-1494
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP heade... Read more
Affected Products : firepower_threat_defense- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2024-50800
Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
4.6
MEDIUMCVE-2024-52523
Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an atta... Read more
Affected Products : notes- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-45969
NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024