Latest CVE Feed
-
8.4
HIGHCVE-2024-37573
The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInter... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-8934
A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-50506
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.9
MEDIUMCVE-2024-10620
A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible ... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-10544
The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.1.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensi... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
8.7
HIGHCVE-2024-0106
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service... Read more
Affected Products : bluefield_1_firmware- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-10399
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-10454
Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click h... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
9.1
CRITICALCVE-2024-48910
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2024-21510
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Att... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
6.4
MEDIUMCVE-2024-9886
The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. T... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-21537
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the d... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-50504
Incorrect Privilege Assignment vulnerability in Matt Whiteman Bulk Change Role allows Privilege Escalation.This issue affects Bulk Change Role: from n/a through 1.1.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
8.6
HIGHCVE-2024-50509
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through 1.0.0.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-50503
Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck Oñate User Toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through 1.2.3.... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
5.5
MEDIUMCVE-2024-50354
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal... Read more
Affected Products : gnark-crypto- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
3.7
LOWCVE-2024-7883
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first us... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.6
MEDIUMCVE-2024-50344
I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
4.8
MEDIUMCVE-2024-30149
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
6.4
MEDIUMCVE-2024-10223
The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's htteamember shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on u... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024