Latest CVE Feed
-
7.5
HIGHCVE-2024-57620
An issue in the trimchars component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57619
An issue in the atom_get_int component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57618
An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57617
An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57616
An issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57615
An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.... Read more
Affected Products : monetdb- Published: Jan. 14, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2024-12298
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: XML External Entity
-
6.6
MEDIUMCVE-2024-12083
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-11396
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the... Read more
Affected Products : event_monster- Published: Jan. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-57811
In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authentication
-
5.8
MEDIUMCVE-2024-56323
OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects ... Read more
Affected Products : openfga- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2024-56138
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of the timestamp feature. During the timestamp signature generation, the revoca... Read more
Affected Products : notation-go- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cryptography
-
3.3
LOWCVE-2024-51491
notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature... Read more
Affected Products : notation-go- Published: Jan. 13, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2024-11128
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injection) without being blocked by AppleMobileFileIntegrity (AMFI). This issue is caused by the absence of Har... Read more
Affected Products : virus_scanner- Published: Jan. 13, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2023-42250
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-42249
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2023-42248
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2023-42247
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-42246
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-42245
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting