Latest CVE Feed
-
7.1
HIGHCVE-2024-34658
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.... Read more
Affected Products : notes- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
8.8
HIGHCVE-2024-8330
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.... Read more
Affected Products : 6shr_system- Published: Aug. 30, 2024
- Modified: Sep. 05, 2024
-
8.8
HIGHCVE-2024-8329
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.... Read more
Affected Products : 6shr_system- Published: Aug. 30, 2024
- Modified: Sep. 05, 2024
-
9.3
CRITICALCVE-2024-7262
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-... Read more
- Actively Exploited
- Published: Aug. 15, 2024
- Modified: Sep. 05, 2024
-
7.8
HIGHCVE-2024-34660
Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.... Read more
Affected Products : notes- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
8.8
HIGHCVE-2024-8102
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to... Read more
Affected Products : wp_extended- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
8.8
HIGHCVE-2024-8104
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber... Read more
Affected Products : wp_extended- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
6.5
MEDIUMCVE-2024-8106
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with... Read more
Affected Products : wp_extended- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
7.1
HIGHCVE-2024-45050
Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loading the conversation is actually a member of that conve... Read more
Affected Products :- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-44808
An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.... Read more
Affected Products :- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
0.0
NACVE-2024-44948
In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant for fine grained caching control of the 640K-1MB region that uses separate MSRs. This fixed ... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
0.0
NACVE-2024-45007
In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref decrement, destroy_workqueue() may be called from within a work item for destroying its own work... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
0.0
NACVE-2024-45008
In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for num_slots is supplied from userspace using ioctl(UI_DEV_CREATE). Since nobody knows p... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
6.1
MEDIUMCVE-2024-43359
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the montagereview via the displayinterval, speed, and scale parameters. This vulnerability is fixed in 1.36.34 and 1.3... Read more
Affected Products : zoneminder- Published: Aug. 12, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-43360
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.... Read more
Affected Products : zoneminder- Published: Aug. 12, 2024
- Modified: Sep. 04, 2024
-
6.1
MEDIUMCVE-2024-43358
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerability in the filter view via the filter[Id]. This vulnerability is fixed in 1.36.34 and 1.37.61.... Read more
Affected Products : zoneminder- Published: Aug. 12, 2024
- Modified: Sep. 04, 2024
-
6.5
MEDIUMCVE-2024-42437
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 04, 2024
-
6.5
MEDIUMCVE-2024-42436
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 04, 2024
-
4.9
MEDIUMCVE-2024-42435
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 04, 2024
-
4.9
MEDIUMCVE-2024-42434
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 04, 2024