Latest CVE Feed
-
6.5
MEDIUMCVE-2024-50424
Missing Authorization vulnerability in Templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through 3.1.5.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-48138
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50422
Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.1.14.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50454
Missing Authorization vulnerability in The SEO Guys at SEOPress SEOPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through 8.1.1.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2019-25219
Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50512
Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping allows Retrieve Embedded Sensitive Data.This issue affects Posti Shipping: from n/a through 3.10.2.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
9.1
CRITICALCVE-2024-48910
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
3.7
LOWCVE-2024-7883
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first us... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
6.9
MEDIUMCVE-2024-10620
A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible ... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2024-21510
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Att... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.5
MEDIUMCVE-2024-50354
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-51419
Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-50506
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-9434
The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the on__translate_options_page() function. This makes it p... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-50508
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through 1.0.0.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
5.7
MEDIUMCVE-2024-49501
Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
8.1
HIGHCVE-2024-42041
The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
4.8
MEDIUMCVE-2024-30149
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
8.4
HIGHCVE-2024-48214
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, e... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.4
MEDIUMCVE-2024-9884
The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. Th... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024