Latest CVE Feed
-
8.1
HIGHCVE-2024-8334
A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file middleware/log.go. The manipulation leads to improper output neutral... Read more
Affected Products : sweet-cms- Published: Aug. 30, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-8335
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the att... Read more
Affected Products : rapidcms- Published: Aug. 30, 2024
- Modified: Sep. 19, 2024
-
8.1
HIGHCVE-2024-8642
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for t... Read more
Affected Products : eclipse_dataspace_components- Published: Sep. 11, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-45388
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature can ... Read more
Affected Products : hoverfly- Published: Sep. 02, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-41869
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-45112
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource i... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-3305
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.... Read more
Affected Products : soliclub- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-3306
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.... Read more
Affected Products : soliclub- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-5546
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 19, 2024
-
8.7
HIGHCVE-2024-7269
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to c... Read more
Affected Products : esp_hr_management- Published: Aug. 28, 2024
- Modified: Sep. 19, 2024
-
8.7
HIGHCVE-2024-6077
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.... Read more
Affected Products : compactlogix_5380_firmware controllogix_5580_firmware compactlogix_5480_firmware guardlogix_5580_firmware compactlogix_5380 compact_guardlogix_5380_sil_2_firmware compact_guardlogix_5380_sil_2 compact_guardlogix_5380_sil_3_firmware compact_guardlogix_5380_sil_3 compactlogix_5480 +6 more products- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-27114
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is ... Read more
Affected Products : soplanning- Published: Sep. 11, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUMCVE-2021-22503
Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
9.1
CRITICALCVE-2021-22533
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
7.6
HIGHCVE-2021-22532
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-20440
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by send... Read more
Affected Products : smart_license_utility- Published: Sep. 04, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46701
In the Linux kernel, the following vulnerability has been resolved: libfs: fix infinite directory reads for offset dir After we switch tmpfs dir operations from simple_dir_operations to simple_offset_dir_operations, every rename happened will fill new d... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-8108
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46702
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Mark XDomain as unplugged when router is removed I noticed that when we do discrete host router NVM upgrade and it gets hot-removed from the PCIe side as a result of NVM fi... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46703
In the Linux kernel, the following vulnerability has been resolved: Revert "serial: 8250_omap: Set the console genpd always on if no console suspend" This reverts commit 68e6939ea9ec3d6579eadeab16060339cdeaf940. Kevin reported that this causes a crash ... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024