Latest CVE Feed
-
8.8
HIGHCVE-2024-23898
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowin... Read more
Affected Products : jenkins- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2024-23747
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laud... Read more
Affected Products : modernanet_hospital_management_system_2024- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2024-23224
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2024-23213
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. Processing web content may lead to arbitrary code execution.... Read more
- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
3.3
LOWCVE-2024-23211
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. A user's private browsing activity may be visible in Set... Read more
- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2024-23183
Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 a... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-23181
Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 a... Read more
Affected Products : a-blog_cms- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2024-23170
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a ... Read more
Affected Products : mbed_tls- Published: Jan. 31, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-23032
Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.... Read more
Affected Products : eyoucms- Published: Feb. 01, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-22751
D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.... Read more
- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-22662
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules... Read more
- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-22660
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg... Read more
- Published: Jan. 23, 2024
- Modified: Jun. 20, 2025
-
5.3
MEDIUMCVE-2024-22648
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.... Read more
Affected Products : seo_panel- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2024-22635
WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.... Read more
Affected Products : webcalendar- Published: Jan. 25, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2024-22570
A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : greencms- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2024-22523
Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.... Read more
Affected Products : ifair- Published: Jan. 30, 2024
- Modified: Jun. 20, 2025
-
6.8
MEDIUMCVE-2024-22366
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitr... Read more
Affected Products : wlx222_firmware wlx413_firmware wlx212_firmware wlx313_firmware wlx202_firmware wlx222 wlx413 wlx212 wlx313 wlx202- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2024-21765
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.... Read more
Affected Products : electronic_delivery_check_system electronic_delivery_item_inspection_support_system- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
6.7
MEDIUMCVE-2024-20013
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Issue ... Read more
- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-20011
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146;... Read more
- Published: Feb. 05, 2024
- Modified: Jun. 20, 2025