Latest CVE Feed
-
8.8
HIGHCVE-2024-47180
Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using version < `server-2024-09-25` are vulnerable to a remote execution vulnerability via the JS... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.4
HIGHCVE-2024-41605
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.3
MEDIUMCVE-2024-39319
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions a... Read more
Affected Products : aimeos_frontend_controller- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
4.4
MEDIUMCVE-2024-45042
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’s highest available AAL is `aal1` e... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
4.3
MEDIUMCVE-2024-9155
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.... Read more
- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.1
MEDIUMCVE-2024-8118
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.... Read more
Affected Products : grafana- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45979
A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise the... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45981
A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.9
MEDIUMCVE-2024-47174
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full URLs... Read more
- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
9.1
CRITICALCVE-2024-46627
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-46441
An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). The file extension of an uncompressed file is... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
7.0
HIGHCVE-2024-39364
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and stopping the execution. The commands can be sent to a simple HTTP req... Read more
Affected Products : adam-5630_firmware- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
2.4
LOWCVE-2024-42496
Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device t... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Sep. 30, 2024
-
9.2
CRITICALCVE-2024-22170
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.... Read more
Affected Products : my_cloud_firmware- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.8
MEDIUMCVE-2024-9278
A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of t... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.0
MEDIUMCVE-2024-45745
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.3
MEDIUMCVE-2024-9160
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2024-8310
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.2
CRITICALCVE-2024-3373
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection.This issue affects Website Template: before 1.2.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
6.5
MEDIUMCVE-2024-9275
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion. The attack ma... Read more
Affected Products : 123solar- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024