Latest CVE Feed
-
7.2
HIGHCVE-2024-42502
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.... Read more
Affected Products : arubaos- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
6.9
MEDIUMCVE-2024-5682
Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation.This issue affects Yordam Library Automation System: before 20.1.... Read more
Affected Products : library_automation_system- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
7.6
HIGHCVE-2024-43969
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.12.... Read more
Affected Products : spiffy_calendar- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-21743
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-47001
Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.4
CRITICALCVE-2024-7873
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
6.2
MEDIUMCVE-2024-8939
A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead to a Denial of Service (DoS). The API used for LLM-based sentence or chat completion accepts a best_of paramete... Read more
Affected Products : vllm- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
6.4
MEDIUMCVE-2024-45812
Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget in the module can lead to cros... Read more
Affected Products : vite- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
8.5
HIGHCVE-2024-6406
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Yordam Information Technology Mobile Library Application allows Retrieve Embedded Sensitive Data.This issue affects Mobile Library Application: before 5.0.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
6.5
MEDIUMCVE-2024-43938
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Peters Name Directory allows Reflected XSS.This issue affects Name Directory: from n/a through 1.29.0.... Read more
Affected Products : name_directory- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
6.5
MEDIUMCVE-2024-8969
OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers who have logged into the system to obtain password hashes of all users and administrators.... Read more
Affected Products : omflow- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
7.5
HIGHCVE-2024-8768
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.... Read more
Affected Products : vllm- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-43778
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-41929
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.6
HIGHCVE-2023-47105
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.7
HIGHCVE-2024-7737
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products : 3dexperience- Published: Sep. 19, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-34399
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer suppor... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2024-45813
find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a singl... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
5.0
MEDIUMCVE-2024-46990
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `1... Read more
Affected Products : directus- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.3
CRITICALCVE-2024-7785
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Software Electronic Ticket System allows Reflected XSS, Cross-Site Scripting (XSS).This issue affects Electronic Ticket System: before 2024.08... Read more
Affected Products :- Published: Sep. 19, 2024
- Modified: Sep. 20, 2024