Latest CVE Feed
-
10.0
CRITICALCVE-2024-42489
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vul... Read more
Affected Products : pro_macros- Published: Aug. 12, 2024
- Modified: Sep. 16, 2024
-
5.5
MEDIUMCVE-2024-0102
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful exploit of this vulnerability might lead to denial of s... Read more
- Published: Aug. 08, 2024
- Modified: Sep. 16, 2024
-
8.8
HIGHCVE-2024-0108
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of... Read more
Affected Products : jetson_linux jetson_agx_xavier_16gb jetson_agx_xavier_32gb jetson_agx_xavier_8gb jetson_nano jetson_tx1 jetson_tx2 jetson_tx2_4gb jetson_tx2_nx jetson_tx2i +7 more products- Published: Aug. 08, 2024
- Modified: Sep. 16, 2024
-
9.0
CRITICALCVE-2024-28991
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.... Read more
Affected Products : access_rights_manager- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
8.8
HIGHCVE-2024-28990
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI... Read more
Affected Products : access_rights_manager- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
9.0
CRITICALCVE-2024-45856
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within th... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-45855
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.... Read more
Affected Products : mindsdb- Published: Sep. 12, 2024
- Modified: Sep. 16, 2024
-
7.5
HIGHCVE-2024-21871
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : xeon_d-2799_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-42772
Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : xeon_d-2799_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.8
MEDIUMCVE-2023-43753
Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2024-21829
Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
5.6
MEDIUMCVE-2024-24968
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.9
MEDIUMCVE-2023-23904
NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-41833
A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.7
HIGHCVE-2023-43626
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : atom_c5325_firmware- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
7.2
HIGHCVE-2024-21781
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.8
MEDIUMCVE-2024-23984
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
6.9
MEDIUMCVE-2023-22351
Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
8.3
HIGHCVE-2024-23599
Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024
-
2.5
LOWCVE-2023-25546
Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Sep. 16, 2024
- Modified: Sep. 16, 2024