Latest CVE Feed
-
6.1
MEDIUMCVE-2024-49378
smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the user’s tab. As... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-48204
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
8.2
HIGHCVE-2024-0126
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,... Read more
Affected Products : virtual_gpu- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-9932
The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers ... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
7.2
HIGHCVE-2024-8392
The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.2 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-9933
The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login'... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-9501
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This ma... Read more
Affected Products : wp_social_login_and_register_social_counter- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
6.4
MEDIUMCVE-2024-9116
The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
8.7
HIGHCVE-2020-26307
HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patc... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
8.7
HIGHCVE-2020-26309
Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-9931
The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unau... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
4.3
MEDIUMCVE-2024-9626
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible fo... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
5.5
MEDIUMCVE-2024-44099
There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
7.5
HIGHCVE-2024-44100
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.... Read more
Affected Products : android pixel_6 pixel pixel_2 pixel_2_xl pixel_3 pixel_3_xl pixel_3a pixel_3a_xl pixel_4 +22 more products- Published: Oct. 25, 2024
- Modified: Oct. 28, 2024
-
7.3
HIGHCVE-2024-42020
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.... Read more
Affected Products : one- Published: Sep. 07, 2024
- Modified: Oct. 27, 2024
-
4.4
MEDIUMCVE-2024-20097
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 27, 2024
-
4.4
MEDIUMCVE-2024-20096
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MSV-1... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 27, 2024
-
4.4
MEDIUMCVE-2024-20095
In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996894; Issue ID: MSV-1... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 27, 2024
-
4.4
MEDIUMCVE-2024-20093
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 27, 2024
-
4.4
MEDIUMCVE-2024-20091
In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 27, 2024