Latest CVE Feed
-
7.5
HIGHCVE-2024-45391
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administr... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-42039
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-45441
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-45450
Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 12, 2024
-
8.7
HIGHCVE-2024-34163
Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.... Read more
Affected Products : lapbc510_firmware lapbc710_firmware nuc_x15_laptop_kit_lapac71h_firmware nuc_x15_laptop_kit_lapac71g_firmware nuc_x15_laptop_kit_lapkc71f_firmware nuc_x15_laptop_kit_lapkc71e_firmware nuc_x15_laptop_kit_lapkc51e_firmware lapkc51e_firmware lapkc71e_firmware lapkc71f_firmware +17 more products- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-29015
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
8.2
HIGHCVE-2024-28947
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products : server_board_s2600st_firmware- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-28887
Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-24977
Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : license_manager_for_flexim- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-23908
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : flexlm_license_daemons_for_intel_fpga- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-43782
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repository via openedx-atlas, translations in the edx-platfor... Read more
Affected Products : openedx- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-43791
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 20... Read more
Affected Products : request_store- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
9.3
CRITICALCVE-2024-23497
Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 12, 2024
-
6.9
MEDIUMCVE-2024-8112
A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scriptin... Read more
Affected Products : jeesite- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
7.2
HIGHCVE-2024-8113
Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts,... Read more
Affected Products : pretix- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
6.5
MEDIUMCVE-2024-42364
Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS r... Read more
Affected Products : homepage- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
0.0
NACVE-2024-43826
In the Linux kernel, the following vulnerability has been resolved: nfs: pass explicit offset/count to trace events nfs_folio_length is unsafe to use without having the folio locked and a check for a NULL ->f_mapping that protects against truncations an... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 12, 2024
-
6.5
MEDIUMCVE-2024-42484
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there is no check for the addrs_num field of the group type messag... Read more
Affected Products : esp-now- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-45857
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.... Read more
Affected Products :- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
6.6
MEDIUMCVE-2024-6840
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege... Read more
Affected Products :- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024