Latest CVE Feed
-
9.8
CRITICALCVE-2024-7528
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-7530
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.... Read more
Affected Products : firefox- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
8.1
HIGHCVE-2024-7529
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thund... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.1
CRITICALCVE-2024-7525
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, ... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.1
CRITICALCVE-2024-7522
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-7521
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.6
CRITICALCVE-2024-7519
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunde... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
7.2
HIGHCVE-2024-3659
Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the ro... Read more
- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
7.2
HIGHCVE-2024-41942
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The... Read more
Affected Products : jupyterhub- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
5.9
MEDIUMCVE-2024-42354
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-42355
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and 6.5.8.13, it accepts as parameter a string the feature flag name to silence, b... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
8.3
HIGHCVE-2024-42356
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a ... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-42357
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by ... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-41238
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.... Read more
Affected Products : responsive_school_management_system- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
6.4
MEDIUMCVE-2024-6639
The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This ma... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-41476
AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
7.5
HIGHCVE-2024-42010
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.... Read more
Affected Products : roundcube- Published: Aug. 05, 2024
- Modified: Aug. 12, 2024
-
6.5
MEDIUMCVE-2024-37283
An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.... Read more
Affected Products : elastic_agent- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-5801
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.... Read more
Affected Products : automation_runtime- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
6.1
MEDIUMCVE-2024-7649
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024