Latest CVE Feed
-
9.8
CRITICALCVE-2024-8073
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.... Read more
Affected Products : web_application_firewall- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-44941
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-7884
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in ... Read more
Affected Products : canister_developer_kit_for_the_internet_computer- Published: Sep. 05, 2024
- Modified: Sep. 12, 2024
-
5.0
MEDIUMCVE-2024-6631
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticat... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Aug. 24, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2024-43412
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Use... Read more
Affected Products : xibo- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
4.8
MEDIUMCVE-2024-43413
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can des... Read more
Affected Products : xibo- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
6.4
MEDIUMCVE-2024-45389
Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking up the value of `document.currentScript.src`. Prior to P... Read more
Affected Products : pagefinder- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-45390
@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrus... Read more
Affected Products : template- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-45391
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administr... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-42039
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-45441
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-45450
Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
8.7
HIGHCVE-2024-34163
Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.... Read more
Affected Products : lapbc510_firmware lapbc710_firmware nuc_x15_laptop_kit_lapac71h_firmware nuc_x15_laptop_kit_lapac71g_firmware nuc_x15_laptop_kit_lapkc71f_firmware nuc_x15_laptop_kit_lapkc71e_firmware nuc_x15_laptop_kit_lapkc51e_firmware lapkc51e_firmware lapkc71e_firmware lapkc71f_firmware +17 more products- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-29015
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
8.2
HIGHCVE-2024-28947
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : server_board_s2600st_firmware- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-28887
Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-24977
Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : license_manager_for_flexim- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-23908
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : flexlm_license_daemons_for_intel_fpga- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-43782
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repository via openedx-atlas, translations in the edx-platfor... Read more
Affected Products : openedx- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-43791
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 20... Read more
Affected Products : request_store- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024