Latest CVE Feed
-
7.8
HIGHCVE-2024-45146
Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicio... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45150
Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
5.5
MEDIUMCVE-2024-45145
Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitatio... Read more
Affected Products : lightroom- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45136
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious f... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45137
InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file w... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
4.9
MEDIUMCVE-2024-21193
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with netw... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
4.4
MEDIUMCVE-2024-21192
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: WebLogic Mgmt). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker w... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47424
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47423
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47422
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47421
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47425
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-47888
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Caref... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-41128
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dis... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-47889
Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.1
MEDIUMCVE-2024-9240
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthen... Read more
Affected Products : redi_restaurant_reservation- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-47887
Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP Token authentication. For a... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
5.3
MEDIUMCVE-2024-44762
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.1
MEDIUMCVE-2024-9347
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. ... Read more
Affected Products : wp_extended- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
8.1
HIGHCVE-2024-48918
RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerability that involves a lack of input validation within the RDS AI framework, specifically within the user i... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024