Latest CVE Feed
-
8.4
HIGHCVE-2024-35520
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
8.2
HIGHCVE-2024-8977
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF a... Read more
Affected Products : gitlab- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
5.3
MEDIUMCVE-2024-9596
An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a Git... Read more
Affected Products : gitlab- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
6.5
MEDIUMCVE-2024-9623
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.... Read more
Affected Products : gitlab- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
5.4
MEDIUMCVE-2024-48902
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API... Read more
Affected Products : youtrack- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-9201
The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.... Read more
Affected Products : seur- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
7.3
HIGHCVE-2024-6530
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to rend... Read more
Affected Products : gitlab- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
6.7
MEDIUMCVE-2024-39831
in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.... Read more
Affected Products : openharmony- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
5.5
MEDIUMCVE-2024-39806
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.... Read more
Affected Products : openharmony- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
6.9
MEDIUMCVE-2024-47840
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X ... Read more
Affected Products : apex- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9782
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overf... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
9.0
HIGHCVE-2024-9783
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. The manipulation of the argument curTime leads to buffer overflow. The attack may be ... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-47846
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
Affected Products : cargo- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
6.9
MEDIUMCVE-2024-47847
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
5.9
MEDIUMCVE-2024-48913
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request ... Read more
Affected Products : hono- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
5.3
MEDIUMCVE-2024-9979
A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.... Read more
Affected Products : pyo3- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
7.0
HIGHCVE-2024-47771
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vect... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
8.7
HIGHCVE-2024-47080
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was ... Read more
Affected Products : javascript_sdk- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
3.7
LOWCVE-2024-9506
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-5749
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024