Latest CVE Feed
-
7.5
HIGHCVE-2024-37406
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
7.8
HIGHCVE-2024-45858
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code wil... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.1
CRITICALCVE-2022-25769
ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application. This logic isn't correct, as the regex in the second FilesMatch only checks the filename, no... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-40568
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-44542
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.... Read more
Affected Products : todesk- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
4.3
MEDIUMCVE-2024-45298
Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset function. While setting up SMTP e-mail's on my server, I tested said e-mails by performing a password reset with my test use... Read more
Affected Products : wiki.js- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46049
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46048
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
7.5
HIGHCVE-2024-46047
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46046
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46044
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
5.9
MEDIUMCVE-2024-45040
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with com... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
6.2
MEDIUMCVE-2024-45039
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark ... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-7717
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more
Affected Products : wp_events_manager- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4100
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been block... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4536
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restr... Read more
Affected Products : ip-vault-wp-firewall- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
7.8
HIGHCVE-2024-38210
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-38209
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUM- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.3
MEDIUMCVE-2024-38207
Microsoft Edge (HTML-based) Memory Corruption Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 23, 2024
- Modified: Sep. 19, 2024