Latest CVE Feed
-
7.5
HIGHCVE-2024-8182
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint... Read more
Affected Products : flowise- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
3.7
LOWCVE-2024-43944
Incorrect Authorization vulnerability in Yassine Idrissi Maintenance & Coming Soon Redirect Animation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through 2.1.3.... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
2.0
LOWCVE-2024-2502
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper ... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
6.5
MEDIUMCVE-2024-8303
A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation of the argument username leads to sql injection. It is... Read more
- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
5.5
MEDIUMCVE-2024-7537
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not required to exploit this vulnerability. ... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
7.8
HIGHCVE-2024-7538
oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
7.8
HIGHCVE-2024-7539
oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in o... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
3.3
LOWCVE-2024-7540
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
3.3
LOWCVE-2024-7541
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on ... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
3.3
LOWCVE-2024-7542
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
7.8
HIGHCVE-2024-7546
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
8.0
HIGHCVE-2024-6200
HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions past 2.146.1 (and patches starting fro... Read more
Affected Products : haloitsm- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
5.3
MEDIUMCVE-2024-6201
HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.14... Read more
Affected Products : haloitsm- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-6202
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM version... Read more
Affected Products : haloitsm- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
8.3
HIGHCVE-2024-6203
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by t... Read more
Affected Products : haloitsm- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
4.3
MEDIUMCVE-2024-39751
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID... Read more
Affected Products : infosphere_information_server- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-43111
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.... Read more
Affected Products : firefox- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
5.5
MEDIUMCVE-2024-34636
Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.... Read more
Affected Products : email- Published: Aug. 07, 2024
- Modified: Aug. 29, 2024
-
10.0
CRITICALCVE-2024-42467
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can ... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8210
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024