Latest CVE Feed
-
6.1
MEDIUMCVE-2024-20488
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cr... Read more
Affected Products : unified_communications_manager- Published: Aug. 21, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8387
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8385
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8384
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Fire... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8381
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Th... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 06, 2024
-
8.6
HIGHCVE-2024-45294
The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by variou... Read more
Affected Products :- Published: Sep. 06, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-43240
Improper Privilege Management vulnerability in azzaroco Ultimate Membership Pro allows Privilege Escalation.This issue affects Ultimate Membership Pro: from n/a through 12.6.... Read more
Affected Products : ultimate_membership_pro- Published: Aug. 19, 2024
- Modified: Sep. 06, 2024
-
10.0
CRITICALCVE-2024-43242
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6.... Read more
Affected Products : ultimate_membership_pro- Published: Aug. 19, 2024
- Modified: Sep. 06, 2024
-
7.5
HIGHCVE-2024-7693
Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the remote server.... Read more
Affected Products : raidenmaild- Published: Aug. 12, 2024
- Modified: Sep. 06, 2024
-
5.3
MEDIUMCVE-2024-25584
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF... Read more
Affected Products :- Published: Sep. 06, 2024
- Modified: Sep. 06, 2024
-
6.0
MEDIUMCVE-2024-45405
`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installati... Read more
Affected Products :- Published: Sep. 06, 2024
- Modified: Sep. 06, 2024
-
6.5
MEDIUMCVE-2024-45074
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
8.8
HIGHCVE-2024-45075
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
9.9
CRITICALCVE-2024-45076
IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
6.9
MEDIUMCVE-2024-8414
A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched re... Read more
Affected Products : insurance_management_system- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8415
A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /routers/add-ticket.php. The manipulation of the argument id leads to sql injectio... Read more
Affected Products : food_ordering_management_system- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8416
A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. It... Read more
Affected Products : food_ordering_management_system- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
6.2
MEDIUMCVE-2023-7265
Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability... Read more
- Published: Aug. 08, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-44956
In the Linux kernel, the following vulnerability has been resolved: drm/xe/preempt_fence: enlarge the fence critical section It is really easy to introduce subtle deadlocks in preempt_fence_work_func() since we operate on single global ordered-wq for si... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-44957
In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Switch from mutex to spinlock for irqfds irqfd_wakeup() gets EPOLLHUP, when it is called by eventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which gets calle... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Sep. 06, 2024