Latest CVE Feed
-
8.8
HIGHCVE-2024-47180
Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using version < `server-2024-09-25` are vulnerable to a remote execution vulnerability via the JS... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45980
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their acco... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
4.0
MEDIUMCVE-2024-45989
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat da... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45981
A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
4.3
MEDIUMCVE-2024-9155
Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.... Read more
- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.4
HIGHCVE-2024-41605
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45982
A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their ... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.5
HIGHCVE-2024-7400
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.... Read more
- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
6.7
MEDIUMCVE-2024-30134
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.1
MEDIUMCVE-2024-8118
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.... Read more
Affected Products : grafana- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
8.8
HIGHCVE-2024-45979
A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise the... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
4.4
MEDIUMCVE-2024-45042
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’s highest available AAL is `aal1` e... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.9
MEDIUMCVE-2024-47174
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full URLs... Read more
- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
5.3
MEDIUMCVE-2024-39319
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions a... Read more
Affected Products : aimeos_frontend_controller- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
6.5
MEDIUMCVE-2024-9294
A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username l... Read more
Affected Products : dingfanzu- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
8.7
HIGHCVE-2024-6436
An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to the server and cause a denial-of-service condition. If exploited, the device would become unresponsive, a... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
7.5
HIGHCVE-2024-45773
A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.... Read more
Affected Products : thrift- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
4.8
MEDIUMCVE-2024-9283
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The e... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2024-6981
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024
-
5.8
MEDIUMCVE-2024-9278
A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of t... Read more
Affected Products :- Published: Sep. 27, 2024
- Modified: Sep. 30, 2024