Latest CVE Feed
-
9.9
CRITICALCVE-2024-47553
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote a... Read more
Affected Products : sinec_security_monitor- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
5.4
MEDIUMCVE-2024-47951
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings... Read more
Affected Products : teamcity- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
5.4
MEDIUMCVE-2024-47950
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings... Read more
Affected Products : teamcity- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
7.5
HIGHCVE-2024-47949
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location... Read more
Affected Products : teamcity- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
7.5
HIGHCVE-2024-47948
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups... Read more
Affected Products : teamcity- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
6.5
MEDIUMCVE-2024-47161
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API... Read more
Affected Products : teamcity- Published: Oct. 08, 2024
- Modified: Oct. 11, 2024
-
9.8
CRITICALCVE-2024-44400
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.... Read more
- Published: Sep. 04, 2024
- Modified: Oct. 11, 2024
-
7.1
HIGHCVE-2024-45932
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.... Read more
Affected Products : krayin_crm- Published: Oct. 07, 2024
- Modified: Oct. 11, 2024
-
9.8
CRITICALCVE-2024-46446
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.... Read more
Affected Products : mecha- Published: Oct. 07, 2024
- Modified: Oct. 11, 2024
-
9.8
CRITICALCVE-2024-45115
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or ele... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
8.1
HIGHCVE-2024-45116
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially craft... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
7.6
HIGHCVE-2024-45117
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to read files from the... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
6.5
MEDIUMCVE-2024-45118
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-45121
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-45122
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
6.1
MEDIUMCVE-2024-45123
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScrip... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
7.1
HIGHCVE-2024-47651
This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by including multiple “userid” parameters in the API request body l... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-9421
The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : login_logout_shortcode- Published: Oct. 04, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-9445
The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medium_posts shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user suppl... Read more
Affected Products : display_medium_posts- Published: Oct. 04, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-8804
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it pos... Read more
Affected Products : code_embed- Published: Oct. 04, 2024
- Modified: Oct. 10, 2024