Latest CVE Feed
-
6.4
MEDIUMCVE-2024-8964
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possib... Read more
Affected Products : sirv- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-3057
A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.3
MEDIUMCVE-2024-9622
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transitio... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
3.1
LOWCVE-2024-47780
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowe... Read more
Affected Products : typo3- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.1
MEDIUMCVE-2024-8629
The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.3.7. This makes it ... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
7.0
HIGHCVE-2024-7206
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.3
CRITICALCVE-2023-52952
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 18 pro (J31032-K2017-H260) (All versions >= V... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
2.5
LOWCVE-2024-27457
Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access.... Read more
Affected Products : tdx_module_software- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-47823
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actua... Read more
Affected Products : livewire- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.1
MEDIUMCVE-2024-47095
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-41798
A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass th... Read more
Affected Products : sentron_pac3200_firmware- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.1
MEDIUMCVE-2024-46886
The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate user ... Read more
Affected Products : simatic_drive_controller_cpu_1504d_tf_firmware simatic_drive_controller_cpu_1507d_tf_firmware simatic_s7-1500_cpu_1510sp_f-1_pn_firmware simatic_s7-1500_cpu_1510sp-1_pn_firmware simatic_s7-1500_cpu_1511-1_pn_firmware simatic_s7-1500_cpu_1511c-1_pn_firmware simatic_s7-1500_cpu_1511f-1_pn_firmware simatic_s7-1500_cpu_1511t-1_pn_firmware simatic_s7-1500_cpu_1511tf-1_pn_firmware simatic_s7-1500_cpu_1512c-1_pn_firmware +55 more products- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
8.7
HIGHCVE-2024-8626
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected product... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
7.5
HIGHCVE-2024-25885
An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
7.3
HIGHCVE-2024-3506
A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-8431
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it pos... Read more
Affected Products : robo_gallery- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
4.9
MEDIUMCVE-2024-36814
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.3
MEDIUMCVE-2024-9620
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between th... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.2
MEDIUMCVE-2024-35215
NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Netwo... Read more
Affected Products : qnx_software_development_platform- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
8.0
HIGHCVE-2024-45880
A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC addr... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024