Latest CVE Feed
-
5.1
MEDIUMCVE-2024-9807
A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scri... Read more
Affected Products : classroombookings- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
5.3
MEDIUMCVE-2024-9806
A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross ... Read more
Affected Products : classroombookings- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47962
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to ex... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47963
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code ... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47964
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute ... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47965
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code i... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
8.4
HIGHCVE-2024-47966
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.... Read more
Affected Products : cncsoft-g2- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
6.1
MEDIUMCVE-2024-9799
A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/... Read more
Affected Products : profile_registration_without_reload\/refresh- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-39586
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9790
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The e... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9789
A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The explo... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9788
A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The explo... Read more
Affected Products : lylme_spage- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2024-7049
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.... Read more
Affected Products : open_webui- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.8
HIGHCVE-2024-9780
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
7.1
HIGHCVE-2024-46865
In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 17, 2024
-
7.8
HIGHCVE-2024-46859
In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses The panasonic laptop code in various places uses the SINF array with index values of 0 - SINF_CUR_BRIGHT(0x0d) with... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 17, 2024
-
4.7
MEDIUMCVE-2024-46710
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to read and compare the cursor buffer. These maps can race with each other in simple scenari... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Oct. 17, 2024
-
4.4
MEDIUMCVE-2024-46695
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS f... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Oct. 17, 2024
-
5.5
MEDIUMCVE-2023-52904
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix possible NULL pointer dereference in snd_usb_pcm_has_fixed_rate() The subs function argument may be NULL, so do not use it before the NULL check.... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Oct. 17, 2024
-
7.1
HIGHCVE-2024-45060
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading t... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 17, 2024