Latest CVE Feed
-
6.5
MEDIUMCVE-2024-4210
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 23, 2024
-
8.0
HIGHCVE-2024-7448
Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this ... Read more
Affected Products : axiom- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
7.8
HIGHCVE-2024-6141
Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code on ... Read more
Affected Products : windscribe- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
7.8
HIGHCVE-2024-5930
VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the abil... Read more
Affected Products : advanced_security- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
7.8
HIGHCVE-2024-5929
VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain... Read more
Affected Products : advanced_security- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
7.8
HIGHCVE-2024-5928
VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. An attacker must first obtain the ability to ex... Read more
Affected Products : advanced_security- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.1
HIGHCVE-2024-5762
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability... Read more
Affected Products : zen_cart- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.8
HIGHCVE-2024-7327
A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php. The manipulation of the argument nickName leads to sql injection. The att... Read more
- Published: Jul. 31, 2024
- Modified: Aug. 23, 2024
-
8.8
HIGHCVE-2024-7795
Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharg... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
7.8
HIGHCVE-2024-7604
Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is required to exp... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.1
HIGHCVE-2024-7603
Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is requ... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-7602
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.1
HIGHCVE-2024-7601
Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentica... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.1
HIGHCVE-2024-7600
Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exp... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-7329
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It... Read more
Affected Products : youdiancms- Published: Jul. 31, 2024
- Modified: Aug. 23, 2024
-
6.1
MEDIUMCVE-2024-43407
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax highligh... Read more
Affected Products : ckeditor- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-43371
CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote files i... Read more
Affected Products : ckan- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.2
HIGHCVE-2024-37311
Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2024-43105
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
8.8
HIGHCVE-2024-7559
The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for a... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024