Latest CVE Feed
-
5.5
MEDIUMCVE-2023-52893
In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars ca... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
8.8
HIGHCVE-2024-44845
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 11, 2024
-
6.5
MEDIUMCVE-2024-6852
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : wp_multitasking- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
4.7
MEDIUMCVE-2022-48899
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix GEM handle creation UAF Userspace can guess the handle value and try to race GEM object creation with handle close, resulting in a use-after-free if we dereference the o... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
6.5
MEDIUMCVE-2024-6853
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack... Read more
Affected Products : wp_multitasking- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
6.5
MEDIUMCVE-2024-6855
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack... Read more
Affected Products : wp_multitasking- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
6.5
MEDIUMCVE-2024-6856
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : wp_multitasking- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
5.4
MEDIUMCVE-2024-6859
The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perf... Read more
Affected Products : wp_multitasking- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
4.7
MEDIUMCVE-2022-48898
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: do not complete dp_aux_cmd_fifo_tx() if irq is not for aux transfer There are 3 possible interrupt sources are handled by DP controller, HPDstatus, Controller state changes ... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
9.8
CRITICALCVE-2024-6924
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.... Read more
Affected Products : truebooker- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
4.3
MEDIUMCVE-2024-6925
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.... Read more
Affected Products : truebooker- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
5.5
MEDIUMCVE-2022-48897
In the Linux kernel, the following vulnerability has been resolved: arm64/mm: fix incorrect file_map_count for invalid pmd The page table check trigger BUG_ON() unexpectedly when split hugepage: ------------[ cut here ]------------ kernel BUG at mm/p... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
9.8
CRITICALCVE-2024-8570
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attac... Read more
Affected Products : tailoring_management_system- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
5.5
MEDIUMCVE-2022-48896
In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix pci device refcount leak As the comment of pci_get_domain_bus_and_slot() says, it returns a PCI device with refcount incremented, when finish using it, the caller must decrem... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
5.3
MEDIUMCVE-2024-8571
A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure throug... Read more
Affected Products : roll_cms- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
5.5
MEDIUMCVE-2022-48895
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: Don't unregister on shutdown Michael Walle says he noticed the following stack trace while performing a shutdown with "reboot -f". He suggests he got "lucky" and just hi... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
6.1
MEDIUMCVE-2024-8572
A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. The manipulation of the argument alias leads to cross site scripti... Read more
Affected Products : golang_cms- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
5.5
MEDIUMCVE-2022-48894
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Don't unregister on shutdown Similar to SMMUv2, this driver calls iommu_device_unregister() from the shutdown path, which removes the IOMMU groups with no coordinatio... Read more
Affected Products : linux_kernel- Published: Aug. 21, 2024
- Modified: Sep. 11, 2024
-
6.1
MEDIUMCVE-2024-42341
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')... Read more
Affected Products : queuemetrics- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024
-
4.3
MEDIUMCVE-2024-42342
Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')... Read more
Affected Products : queuemetrics- Published: Sep. 08, 2024
- Modified: Sep. 11, 2024