Latest CVE Feed
-
5.5
MEDIUMCVE-2024-8264
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.... Read more
Affected Products : robot_schedule- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
2.7
LOWCVE-2024-40884
Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.... Read more
- Published: Aug. 22, 2024
- Modified: Oct. 17, 2024
-
9.8
CRITICALCVE-2024-8080
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,datab... Read more
Affected Products : online_health_care_system- Published: Aug. 22, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-47828
ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a req... Read more
Affected Products : ampache- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-47767
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not ha... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-47766
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the conte... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-9548
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This ... Read more
Affected Products : slimstat_analytics- Published: Oct. 15, 2024
- Modified: Oct. 17, 2024
-
5.3
MEDIUMCVE-2024-9546
The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution resul... Read more
Affected Products : wpide- Published: Oct. 15, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-43559
Windows Mobile Broadband Driver Denial of Service Vulnerability... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_21h2 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 +1 more products- Published: Oct. 08, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-43558
Windows Mobile Broadband Driver Denial of Service Vulnerability... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_21h2 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 +1 more products- Published: Oct. 08, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-43557
Windows Mobile Broadband Driver Denial of Service Vulnerability... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_21h2 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 +1 more products- Published: Oct. 08, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-45738
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG loggi... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-45739
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2024-45740
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through Scheduled Views that could result i... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2024-45741
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom conf... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
8.0
HIGHCVE-2024-45731
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows Syst... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
7.1
HIGHCVE-2024-45732
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles cou... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
8.2
HIGHCVE-2024-9466
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
9.3
CRITICALCVE-2024-9464
An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API ke... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
5.3
MEDIUMCVE-2024-47044
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Oct. 17, 2024