Latest CVE Feed
-
5.5
MEDIUMCVE-2024-49980
In the Linux kernel, the following vulnerability has been resolved: vrf: revert "vrf: Remove unnecessary RCU-bh critical section" This reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853. dev_queue_xmit_nit is expected to be called with BH disabled... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2022-49000
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix PCI device refcount leak in has_external_pci() for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the refe... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49637
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through 2.1.... Read more
Affected Products : bet_wc_2018_russia- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49636
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Prashant Mavinkurve Agile Video Player Lite allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through 1.0.... Read more
Affected Products : agile_video_player_lite- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2022-48999
In the Linux kernel, the following vulnerability has been resolved: ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference Gwangun Jung reported a slab-out-of-bounds access in fib_nh_match: fib_nh_match+0xf98/0x1130 li... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 31, 2024
-
7.2
HIGHCVE-2024-41153
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privil... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2024-20462
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability i... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
6.1
MEDIUMCVE-2024-20460
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user. This vulnerability ... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-20421
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affec... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2024-20420
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user. This vulnerability is due to incorrect ... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
5.2
MEDIUMCVE-2021-46746
Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-46977
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to d... Read more
Affected Products : cosmos- Published: Oct. 02, 2024
- Modified: Oct. 31, 2024
-
6.1
MEDIUMCVE-2024-43795
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: Thi... Read more
Affected Products : cosmos- Published: Oct. 02, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-44203
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access a user's Photos Library.... Read more
Affected Products : macos- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-50497
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering... Read more
Affected Products : advanced_online_ordering_and_delivery_platform- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50501
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Climax Themes Kata Plus allows Stored XSS.This issue affects Kata Plus: from n/a through 1.4.7.... Read more
Affected Products : kata_plus- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.5
MEDIUMCVE-2024-50502
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.18.... Read more
Affected Products : cozy_blocks- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
4.4
MEDIUMCVE-2024-47974
Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 31, 2024
-
4.4
MEDIUMCVE-2024-47968
Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 31, 2024
-
3.1
LOWCVE-2024-21251
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure pr... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 31, 2024