Latest CVE Feed
-
5.8
MEDIUMCVE-2024-9278
A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of t... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
6.5
MEDIUMCVE-2024-9294
A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username l... Read more
Affected Products : dingfanzu- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
4.8
MEDIUMCVE-2024-9283
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The e... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
7.3
HIGHCVE-2024-40509
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
7.0
HIGHCVE-2024-39364
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP req... Read more
Affected Products : adam-5630_firmware- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-46441
An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). The file extension of an uncompressed file is... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2024-8310
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.3
MEDIUMCVE-2024-9160
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.0
MEDIUMCVE-2024-45745
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.2
CRITICALCVE-2024-3373
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection.This issue affects Website Template: before 1.2.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
6.5
MEDIUMCVE-2024-9275
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion. The attack ma... Read more
Affected Products : 123solar- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2024-6981
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.2
CRITICALCVE-2024-22170
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.... Read more
Affected Products : my_cloud_firmware- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.3
MEDIUMCVE-2024-9276
A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the a... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.5
MEDIUMCVE-2024-46769
In the Linux kernel, the following vulnerability has been resolved: spi: intel: Add check devm_kasprintf() returned value intel_spi_populate_chip() use devm_kasprintf() to set pdata->name. This can return a NULL pointer on failure but this returned valu... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 30, 2024
-
5.5
MEDIUMCVE-2024-46797
In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an interrupt occurs in queued_spin_lock_slowpath() after we increment qnodesp->count and before node->lock is initialized, another CPU mi... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 29, 2024
-
6.5
MEDIUMCVE-2022-39068
There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could use the vulnerability to perform a denial of service attack.... Read more
- Published: Sep. 18, 2024
- Modified: Sep. 29, 2024
-
5.4
MEDIUMCVE-2024-39910
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being upload... Read more
Affected Products : decidim- Published: Sep. 16, 2024
- Modified: Sep. 29, 2024
-
5.9
MEDIUM- Published: Sep. 17, 2024
- Modified: Sep. 29, 2024
-
4.9
MEDIUMCVE-2024-43188
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation.... Read more
Affected Products : business_automation_workflow- Published: Sep. 18, 2024
- Modified: Sep. 29, 2024