Latest CVE Feed
-
7.8
HIGHCVE-2024-7679
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.... Read more
Affected Products : ui_for_wpf- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
5.5
MEDIUMCVE-2024-46857
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix bridge mode operations when there are no VFs Currently, trying to set the bridge mode attribute when numvfs=0 leads to a crash: bridge link set dev eth2 hwmode vepa [ 1... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
5.5
MEDIUMCVE-2024-46867
In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() There is a real deadlock as well as sleeping in atomic() bug in here, if the bo put happens to be the last ref, since bo destruction wants ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
5.5
MEDIUMCVE-2024-46866
In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: add missing bo locking in show_meminfo() bo_meminfo() wants to inspect bo state like tt and the ttm resource, however this state can change at any point leading to stuff ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
5.5
MEDIUMCVE-2024-46868
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire() If the __qcuefi pointer is not set, then in the original code, we would hold onto the lock. That means that if we tried to ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-43692
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.... Read more
- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
10.0
CRITICALCVE-2024-45066
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.... Read more
- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-45373
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.... Read more
- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
9.1
CRITICALCVE-2024-6592
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue a... Read more
- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
5.5
MEDIUMCVE-2024-46856
In the Linux kernel, the following vulnerability has been resolved: net: phy: dp83822: Fix NULL pointer dereference on DP83825 devices The probe() function is only used for DP83822 and DP83826 PHY, leaving the private data pointer uninitialized for the ... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-8890
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate credentials or steal sessions due to the fact that the device only implements the HTTP protocol. This fact prevents a secure ... Read more
- Published: Sep. 18, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-43423
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.... Read more
- Published: Sep. 25, 2024
- Modified: Oct. 01, 2024
-
7.8
HIGHCVE-2024-43405
Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature check and possibly ... Read more
Affected Products : nuclei- Published: Sep. 04, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-43402
Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust version 1.81.0, it was possible to bypass the fix when the batch fi... Read more
Affected Products : rust- Published: Sep. 04, 2024
- Modified: Oct. 01, 2024
-
6.4
MEDIUMCVE-2024-9023
The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products : wp-webauthn- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
6.1
MEDIUMCVE-2024-8715
The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated atta... Read more
Affected Products : simple_ldap_login- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
6.4
MEDIUMCVE-2024-8547
The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] shortcode in all versions up to, and including, 4.5 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products : simple_popup_plugin- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
10.0
CRITICALCVE-2024-8353
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address... Read more
Affected Products : givewp- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
7.5
HIGHCVE-2024-9136
Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024
-
7.5
HIGHCVE-2024-47294
Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 01, 2024