Latest CVE Feed
-
5.4
MEDIUMCVE-2024-41841
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-44382
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-44381
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-45256
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add i... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-8161
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve ... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-7656
The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of untrusted input in the 'devvn_ihotspot_shortcode_func' function. This makes it possible for authentica... Read more
Affected Products :- Published: Aug. 24, 2024
- Modified: Aug. 26, 2024
-
8.2
HIGHCVE-2024-43444
Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: * OTRS... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.9
MEDIUMCVE-2024-43443
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.8
MEDIUMCVE-2024-41774
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : common_licensing- Published: Aug. 13, 2024
- Modified: Aug. 24, 2024
-
9.8
CRITICALCVE-2024-7934
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file execute.php. The manipulation of the argument code leads to sql injec... Read more
Affected Products : project_expense_monitoring_system- Published: Aug. 19, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-7933
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file login1.php of the component Backend Login. The manipulation of the argument user leads to sql ... Read more
Affected Products : project_expense_monitoring_system- Published: Aug. 19, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-7935
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file print.php. The manipulation of the argument map_id leads to sql injection. The... Read more
Affected Products : project_expense_monitoring_system- Published: Aug. 19, 2024
- Modified: Aug. 23, 2024
-
6.1
MEDIUMCVE-2024-42852
Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.... Read more
Affected Products :- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
7.5
HIGHCVE-2023-50314
IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain se... Read more
Affected Products : websphere_application_server- Published: Aug. 14, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-35152
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.... Read more
Affected Products : db2- Published: Aug. 14, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-37529
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 294295.... Read more
Affected Products : db2- Published: Aug. 14, 2024
- Modified: Aug. 23, 2024
-
6.8
MEDIUMCVE-2024-24580
Improper conditions check in some Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow a privileged user to potentially enable denial of service via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-7954
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.... Read more
Affected Products : spip- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.8
MEDIUMCVE-2024-7427
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Network Node Manager i (NNMi) could allow Cross-Site Scripting (XSS).This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05,... Read more
Affected Products :- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
6.1
MEDIUMCVE-2024-43794
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specia... Read more
Affected Products :- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024