Latest CVE Feed
-
8.8
HIGHCVE-2024-40431
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as ... Read more
Affected Products :- Published: Oct. 23, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-9598
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible... Read more
Affected Products : accelerated_mobile_pages- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10016
The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.1
MEDIUMCVE-2024-9214
The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to ins... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10112
The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This make... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10176
The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embed_player shortcode in all versions up to, and including, 1.9.13 due to insufficient input sanitization and output escaping on user supp... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.1
HIGHCVE-2024-10327
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user lo... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
8.6
HIGHCVE-2024-10313
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
6.1
MEDIUMCVE-2024-10332
A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint “/abonados/public/janto/m... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10343
The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
9.3
CRITICALCVE-2024-49681
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SWIT WP Sessions Time Monitoring Full Automatic allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
5.5
MEDIUMCVE-2024-47173
Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 25, 2024
-
5.5
MEDIUMCVE-2024-49870
In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix dentry leak in cachefiles_open_file() A dentry leak may be caused when a lookup cookie and a cull are concurrent: P1 | P2 ----------... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 25, 2024
-
7.1
HIGHCVE-2024-44061
: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPFactory EU/UK VAT Manager for WooCommerce allows Cross-Site Scripting (XSS).This issue affects EU/UK VAT Manager for WooCommerce: from n/a through 2.12.14.... Read more
Affected Products : eu\/uk_vat_manager_for_woocommerce- Published: Oct. 20, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-7973
Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Oct. 24, 2024
-
8.8
HIGHCVE-2024-7535
Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Oct. 24, 2024
-
7.5
HIGHCVE-2024-42986
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Oct. 24, 2024
-
7.5
HIGHCVE-2024-42977
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
- Published: Aug. 15, 2024
- Modified: Oct. 24, 2024
-
9.8
CRITICALCVE-2024-42966
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.... Read more
- Published: Aug. 15, 2024
- Modified: Oct. 24, 2024
-
8.8
HIGHCVE-2023-49233
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow atta... Read more
Affected Products :- Published: Sep. 03, 2024
- Modified: Oct. 24, 2024