Latest CVE Feed
-
9.8
CRITICALCVE-2024-43399
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extr... Read more
Affected Products : mobile_security_framework- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2024-7922
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 a... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-120_firmware dnr-202l_firmware dns-315l_firmware dns-320lw_firmware dns-321_firmware dns-323_firmware dns-325_firmware +50 more products- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.1
CRITICALCVE-2024-38891
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: Aug. 20, 2024
-
8.8
HIGHCVE-2024-42633
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.... Read more
- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2024-38887
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary priv... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: Aug. 20, 2024
-
7.5
HIGHCVE-2024-6348
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.... Read more
- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
7.8
HIGHCVE-2024-32927
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
7.5
HIGHCVE-2024-42657
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process... Read more
- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2024-42658
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter... Read more
- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.0
CRITICALCVE-2024-43400
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engin... Read more
Affected Products : xwiki- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
9.0
CRITICALCVE-2024-43401
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The u... Read more
Affected Products : xwiki- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
7.5
HIGHCVE-2024-7924
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit ha... Read more
Affected Products : zzcms- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
7.5
HIGHCVE-2024-7925
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosu... Read more
Affected Products : zzcms- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
5.1
MEDIUMCVE-2024-7453
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component Attachment Management Section. The ma... Read more
Affected Products : fastadmin- Published: Aug. 04, 2024
- Modified: Aug. 20, 2024
-
8.8
HIGHCVE-2024-7827
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of suff... Read more
Affected Products : wp_easycart- Published: Aug. 20, 2024
- Modified: Aug. 20, 2024
-
7.5
HIGHCVE-2024-6918
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.... Read more
Affected Products : accutech_manager- Published: Aug. 20, 2024
- Modified: Aug. 20, 2024
-
7.2
HIGHCVE-2022-1206
The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension sanitization in the adrotate_insert_media() function in all versions up to, and including, 5.13.2. Thi... Read more
Affected Products :- Published: Aug. 20, 2024
- Modified: Aug. 20, 2024
-
5.4
MEDIUMCVE-2024-43326
Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.... Read more
Affected Products :- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024
-
6.5
MEDIUMCVE-2024-25009
Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation.... Read more
Affected Products :- Published: Aug. 20, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2024-43354
Deserialization of Untrusted Data vulnerability in myCred allows Object Injection.This issue affects myCred: from n/a through 2.7.2.... Read more
Affected Products : mycred- Published: Aug. 19, 2024
- Modified: Aug. 20, 2024