Latest CVE Feed
-
4.6
MEDIUMCVE-2024-29075
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
8.0
HIGHCVE-2024-45827
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may exec... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
3.5
LOWCVE-2024-47587
Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
5.4
MEDIUMCVE-2024-10790
The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.5.1 due to insufficient input sanitization and output escaping. This makes it possible for... Read more
Affected Products : admin_and_site_enhancements- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
5.8
MEDIUMCVE-2024-23983
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.... Read more
Affected Products : pingaccess- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-42372
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-47295
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versions, see the inf... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Nov. 11, 2024
-
8.9
HIGHCVE-2024-7059
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.... Read more
Affected Products : security_center- Published: Nov. 05, 2024
- Modified: Nov. 09, 2024
-
7.8
HIGH- Published: Oct. 08, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-44021
Missing Authorization vulnerability in Truepush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Truepush: from n/a through 1.0.8.... Read more
Affected Products : truepush- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50109
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null ptr dereference in raid10_size() In raid10_run() if raid10_set_queue_limits() succeed, the return value is set to zero, and if following procedures failed raid10_run... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-6762
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50108
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too Stuart Hayhurst has found that both at bootup and fullscreen VA-API video is leading to black screens for around 1 second and ke... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50107
In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses Commit 50c6dbdfd16e ("x86/ioremap: Improve iounmap() address range checks") introduces a WARN when adrre... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-44031
Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.6.3.... Read more
Affected Products : joomsport- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-44038
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 3.2.9.... Read more
Affected Products : sunshine_photo_cart- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-44052
Missing Authorization vulnerability in HelloAsso allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HelloAsso: from n/a through 1.1.10.... Read more
Affected Products : helloasso- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-10028
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process... Read more
Affected Products : everest_backup- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-10647
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.244... Read more
Affected Products : ws_form- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
8.1
HIGHCVE-2024-10020
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possi... Read more
Affected Products : social_login- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024