Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.4

    HIGH
    CVE-2024-6473

    Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.... Read more

    Affected Products : yandex_browser
    • Published: Sep. 03, 2024
    • Modified: Sep. 05, 2024
  • 5.3

    MEDIUM
    CVE-2024-8411

    A vulnerability, which was classified as problematic, has been found in ABCD ABCD2 up to 2.2.0-beta-1. This issue affects some unknown processing of the file /buscar_integrada.php. The manipulation of the argument Sub_Expresion leads to cross site scripti... Read more

    Affected Products : abcd
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 9.6

    CRITICAL
    CVE-2024-7345

    Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release pla... Read more

    Affected Products : openedge
    • Published: Sep. 03, 2024
    • Modified: Sep. 05, 2024
  • 7.2

    HIGH
    CVE-2024-7346

    Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overrid... Read more

    Affected Products : openedge
    • Published: Sep. 03, 2024
    • Modified: Sep. 05, 2024
  • 8.3

    HIGH
    CVE-2024-7654

    An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM ... Read more

    Affected Products : openedge
    • Published: Sep. 03, 2024
    • Modified: Sep. 05, 2024
  • 7.5

    HIGH
    CVE-2024-34659

    Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.... Read more

    Affected Products : group_sharing
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 9.8

    CRITICAL
    CVE-2024-34657

    Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.... Read more

    Affected Products : notes
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 7.1

    HIGH
    CVE-2024-34658

    Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.... Read more

    Affected Products : notes
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 8.8

    HIGH
    CVE-2024-8330

    6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.... Read more

    Affected Products : 6shr_system
    • Published: Aug. 30, 2024
    • Modified: Sep. 05, 2024
  • 8.8

    HIGH
    CVE-2024-8329

    6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.... Read more

    Affected Products : 6shr_system
    • Published: Aug. 30, 2024
    • Modified: Sep. 05, 2024
  • 9.3

    CRITICAL
    CVE-2024-7262

    Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-... Read more

    Affected Products : wps_office windows
    • Actively Exploited
    • Published: Aug. 15, 2024
    • Modified: Sep. 05, 2024
  • 7.8

    HIGH
    CVE-2024-34660

    Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.... Read more

    Affected Products : notes
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 8.8

    HIGH
    CVE-2024-8102

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to... Read more

    Affected Products : wp_extended
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 8.8

    HIGH
    CVE-2024-8104

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber... Read more

    Affected Products : wp_extended
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 6.5

    MEDIUM
    CVE-2024-8106

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with... Read more

    Affected Products : wp_extended
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 7.1

    HIGH
    CVE-2024-45050

    Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loading the conversation is actually a member of that conve... Read more

    Affected Products :
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 9.8

    CRITICAL
    CVE-2024-44808

    An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.... Read more

    Affected Products :
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 0.0

    NA
    CVE-2024-45008

    In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for num_slots is supplied from userspace using ioctl(UI_DEV_CREATE). Since nobody knows p... Read more

    Affected Products : linux_kernel
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 0.0

    NA
    CVE-2024-45007

    In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref decrement, destroy_workqueue() may be called from within a work item for destroying its own work... Read more

    Affected Products : linux_kernel
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
  • 0.0

    NA
    CVE-2024-44948

    In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant for fine grained caching control of the 640K-1MB region that uses separate MSRs. This fixed ... Read more

    Affected Products : linux_kernel
    • Published: Sep. 04, 2024
    • Modified: Sep. 05, 2024
Showing 20 of 292016 Results