Latest CVE Feed
-
4.3
MEDIUMCVE-2024-6051
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 04, 2024
-
4.8
MEDIUMCVE-2024-46475
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2024-8675
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.2. This makes it possible for authenticated a... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
7.2
HIGHCVE-2024-7869
The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9106
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenti... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8720
The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output esc... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9108
The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticate... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-9267
The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.3. This makes it possible for... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
7.1
HIGHCVE-2024-8981
The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on the URL in all versions up to, and including, 2.4.0.... Read more
Affected Products : broken_link_checker- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-8786
The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthent... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
8.2
HIGHCVE-2024-21489
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
8.8
HIGHCVE-2024-8885
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-9333
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-45186
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
3.3
LOWCVE-2024-0124
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A successful exploit of this vulnerability might lead to a lim... Read more
Affected Products : cuda_toolkit- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
3.3
LOWCVE-2024-0123
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit... Read more
Affected Products : cuda_toolkit- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-35294
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9441
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality ... Read more
Affected Products : emerge_e3_firmware- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.9
MEDIUMCVE-2024-9174
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI... Read more
Affected Products : hubshare- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code v... Read more
Affected Products : october- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024