Latest CVE Feed
-
8.6
HIGHCVE-2024-42352
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly par... Read more
Affected Products : nuxt- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-45457
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.... Read more
Affected Products : spiffy_calendar- Published: Sep. 15, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-7553
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untru... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 +14 more products- Published: Aug. 07, 2024
- Modified: Sep. 19, 2024
-
7.6
HIGHCVE-2024-41959
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to ... Read more
Affected Products : mailcow\- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
4.8
MEDIUMCVE-2024-41960
mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is executed whenever the configuration page is viewed, enabli... Read more
Affected Products : mailcow\- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
6.3
MEDIUMCVE-2024-34343
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly use API's provided by `unjs/ufo`. This library also cont... Read more
Affected Products : nuxt- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-6087
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JWT tokens. These ... Read more
Affected Products : lunary- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
3.9
LOWCVE-2024-45620
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized part... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-31416
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of th... Read more
Affected Products : foreseer_electrical_power_monitoring_system- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
7.1
HIGHCVE-2024-45458
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.... Read more
Affected Products : spiffy_calendar- Published: Sep. 15, 2024
- Modified: Sep. 19, 2024
-
5.9
MEDIUMCVE-2024-45455
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO allows Stored XSS.This issue affects WP Meta SEO: from n/a through 4.5.13.... Read more
Affected Products : wp_meta_seo- Published: Sep. 15, 2024
- Modified: Sep. 19, 2024
-
8.1
HIGHCVE-2024-31415
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine... Read more
Affected Products : foreseer_electrical_power_monitoring_system- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
6.7
MEDIUMCVE-2024-31414
The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injec... Read more
Affected Products : foreseer_electrical_power_monitoring_system- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-45456
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO allows Stored XSS.This issue affects WP Meta SEO: from n/a through 4.5.13.... Read more
Affected Products : wp_meta_seo- Published: Sep. 15, 2024
- Modified: Sep. 19, 2024
-
8.1
HIGHCVE-2024-6862
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user with lo... Read more
Affected Products : lunary- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-6867
An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it ret... Read more
Affected Products : lunary- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
4.8
MEDIUMCVE-2024-7655
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. T... Read more
Affected Products : peepso- Published: Sep. 10, 2024
- Modified: Sep. 19, 2024
-
4.8
MEDIUMCVE-2024-7618
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitiz... Read more
Affected Products : peepso- Published: Sep. 10, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46694
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code wh... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
7.3
HIGHCVE-2024-4554
Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects NetIQ Access Manager before 5.0.4.1 and 5.1.... Read more
Affected Products : netiq_access_manager- Published: Aug. 28, 2024
- Modified: Sep. 19, 2024