Latest CVE Feed
-
7.3
HIGHCVE-2024-10945
A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installa... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-49369
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an ... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
5.0
MEDIUMCVE-2024-51750
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
5.3
MEDIUMCVE-2024-50336
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue a... Read more
Affected Products : javascript_sdk- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
6.5
MEDIUMCVE-2024-52296
libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
3.5
LOWCVE-2024-51749
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a fi... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
5.3
MEDIUMCVE-2024-30133
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.3
HIGHCVE-2024-8937
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to t... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
9.2
CRITICALCVE-2024-8938
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call to t... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
6.6
MEDIUMCVE-2024-28728
Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via a crafted payload to the WiFi SSID Name field.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
7.5
HIGHCVE-2024-4741
Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
9.1
CRITICALCVE-2022-45157
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI a... Read more
Affected Products : rancher- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
4.3
MEDIUMCVE-2024-10852
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authe... Read more
Affected Products : buy_one_click_woocommerce- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
6.1
MEDIUMCVE-2024-10038
The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
4.3
MEDIUMCVE-2024-10794
The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the 'bhf' shortcode due to insufficient restrictions on which posts can be included. This makes it ... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
8.0
HIGHCVE-2024-28726
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.... Read more
Affected Products : dwr-2000m_firmware- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.8
HIGHCVE-2024-2208
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulner... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
6.0
MEDIUMCVE-2024-2207
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulner... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.8
HIGHCVE-2024-10629
The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and including, 2.2.8. This makes it possible for authenticate... Read more
- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024
-
7.7
HIGHCVE-2024-8935
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation... Read more
Affected Products :- Published: Nov. 13, 2024
- Modified: Nov. 13, 2024