Latest CVE Feed
-
5.5
MEDIUMCVE-2024-50080
In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be ... Read more
Affected Products : linux_kernel- Published: Oct. 29, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-47902
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of a... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
5.5
MEDIUMCVE-2024-50081
In the Linux kernel, the following vulnerability has been resolved: blk-mq: setup queue ->tag_set before initializing hctx Commit 7b815817aa58 ("blk-mq: add helper for checking if one CPU is mapped to specified hctx") needs to check queue mapping via ta... Read more
Affected Products : linux_kernel- Published: Oct. 29, 2024
- Modified: Oct. 30, 2024
-
10.0
CRITICALCVE-2024-47901
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of a... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
8.5
HIGHCVE-2024-47904
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected device... Read more
- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
6.5
MEDIUMCVE-2024-44297
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. Processing a maliciously crafted message ... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 30, 2024
-
2.4
LOWCVE-2024-40851
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.... Read more
- Published: Oct. 28, 2024
- Modified: Oct. 30, 2024
-
4.3
MEDIUMCVE-2024-35495
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 30, 2024
-
9.9
CRITICALCVE-2024-3980
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files t... Read more
- Published: Aug. 27, 2024
- Modified: Oct. 30, 2024
-
8.2
HIGHCVE-2024-3982
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not... Read more
Affected Products : microscada_x_sys600- Published: Aug. 27, 2024
- Modified: Oct. 30, 2024
-
9.9
CRITICALCVE-2024-4872
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must ha... Read more
- Published: Aug. 27, 2024
- Modified: Oct. 30, 2024
-
4.3
MEDIUMCVE-2024-7941
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.... Read more
Affected Products : microscada_x_sys600- Published: Aug. 27, 2024
- Modified: Oct. 30, 2024
-
7.5
HIGHCVE-2024-10290
A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file 3/qq-connect2.0/API/com/inc.php. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The ... Read more
Affected Products : zzcms- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-48963
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory ... Read more
Affected Products : snyk_cli- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-10371
A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be use... Read more
Affected Products : payroll_management_system- Published: Oct. 25, 2024
- Modified: Oct. 30, 2024
-
5.5
MEDIUMCVE-2024-50087
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free on read_alloc_one_name() error The function read_alloc_one_name() does not initialize the name field of the passed fscrypt_str struct if kmalloc fa... Read more
Affected Products : linux_kernel- Published: Oct. 29, 2024
- Modified: Oct. 30, 2024
-
5.4
MEDIUMCVE-2024-48119
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.... Read more
Affected Products : vtiger_crm- Published: Oct. 14, 2024
- Modified: Oct. 30, 2024
-
8.8
HIGHCVE-2024-34668
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-10350
A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add-doctor.php. The manipulation of the argument docname leads to sql injection. The at... Read more
- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
8.8
HIGHCVE-2024-34667
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 30, 2024