Latest CVE Feed
-
9.9
CRITICALCVE-2024-38650
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.... Read more
Affected Products : veeam_service_provider_console- Published: Sep. 07, 2024
- Modified: Sep. 09, 2024
-
8.8
HIGHCVE-2024-41160
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 09, 2024
-
5.5
MEDIUMCVE-2024-43859
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to truncate preallocated blocks in f2fs_file_open() chenyuwen reports a f2fs bug as below: Unable to handle kernel NULL pointer dereference at virtual address 000000000000001... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Sep. 08, 2024
-
9.8
CRITICALCVE-2022-33162
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a... Read more
- Published: Aug. 16, 2024
- Modified: Sep. 07, 2024
-
9.8
CRITICALCVE-2024-7454
A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is the function patient_name of the file patients.php. The manipulation leads to sql injection. The attack ma... Read more
- Published: Aug. 04, 2024
- Modified: Sep. 07, 2024
-
9.8
CRITICALCVE-2024-45307
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's sett... Read more
Affected Products : sudobot- Published: Sep. 03, 2024
- Modified: Sep. 07, 2024
-
8.0
HIGHCVE-2024-44796
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.... Read more
Affected Products : picuploader- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.8
HIGHCVE-2024-43804
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functio... Read more
Affected Products : roxy-wi- Published: Aug. 29, 2024
- Modified: Sep. 06, 2024
-
8.1
HIGHCVE-2024-41964
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and deleting languages have already existed and could be confi... Read more
Affected Products : kirby- Published: Aug. 29, 2024
- Modified: Sep. 06, 2024
-
5.4
MEDIUMCVE-2024-44919
A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ad description parameter.... Read more
Affected Products : seacms- Published: Aug. 29, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8255
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.... Read more
Affected Products : dtn_soft- Published: Aug. 29, 2024
- Modified: Sep. 06, 2024
-
10.0
CRITICALCVE-2024-5991
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be N... Read more
Affected Products : wolfssl- Published: Aug. 27, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-7720
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.... Read more
Affected Products : security_manager- Published: Aug. 27, 2024
- Modified: Sep. 06, 2024
-
6.1
MEDIUMCVE-2024-44797
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.... Read more
Affected Products : gazelle- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
6.5
MEDIUMCVE-2024-8165
A vulnerability, which was classified as problematic, was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function exportZip of the file /admin/file_manager/export. The manipulation of the argument path leads to path ... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.8
HIGHCVE-2024-8164
A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/Controllers/FileManagerController.php. The manipulation ... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.1
HIGHCVE-2024-8163
A vulnerability classified as critical was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this vulnerability is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files leads... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.3
HIGHCVE-2024-7570
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.... Read more
Affected Products : neurons_for_itsm- Published: Aug. 13, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-7569
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.... Read more
Affected Products : neurons_for_itsm- Published: Aug. 13, 2024
- Modified: Sep. 06, 2024
-
4.3
MEDIUMCVE-2024-37898
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having del... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024