Latest CVE Feed
-
5.3
MEDIUMCVE-2020-1821
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet... Read more
- Published: Dec. 28, 2024
- Modified: Jan. 13, 2025
-
5.3
MEDIUMCVE-2020-1820
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet... Read more
- Published: Dec. 28, 2024
- Modified: Jan. 13, 2025
-
7.8
HIGHCVE-2024-46973
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.... Read more
Affected Products : ddk- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
7.8
HIGHCVE-2024-46972
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.... Read more
Affected Products : ddk- Published: Dec. 28, 2024
- Modified: Mar. 13, 2025
-
7.8
HIGHCVE-2024-43705
Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only system files that have been mapped into application memory.... Read more
Affected Products : ddk- Published: Dec. 28, 2024
- Modified: Dec. 28, 2024
-
4.8
MEDIUMCVE-2024-54775
Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions.... Read more
Affected Products : dcat_admin- Published: Dec. 27, 2024
- Modified: Apr. 22, 2025
-
4.8
MEDIUMCVE-2024-54774
Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.... Read more
Affected Products : dcat_admin- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
7.5
HIGHCVE-2024-50714
A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted script to the /FB/getFbVideoSource.php component.... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 28, 2024
-
9.8
CRITICALCVE-2024-50717
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 18, 2025
-
9.8
CRITICALCVE-2024-50716
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
7.5
HIGHCVE-2024-50715
An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the /youtubeInfo.php component.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2024-50713
SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.... Read more
Affected Products : smart_agent- Published: Dec. 27, 2024
- Modified: Apr. 21, 2025
-
9.3
CRITICALCVE-2024-56732
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.... Read more
Affected Products : harfbuzz- Published: Dec. 27, 2024
- Modified: Dec. 28, 2024
-
5.3
MEDIUMCVE-2024-54454
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attack... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 31, 2024
-
7.5
HIGHCVE-2024-54453
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web applicati... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 31, 2024
-
4.9
MEDIUMCVE-2024-54452
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the ... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 28, 2024
-
4.8
MEDIUMCVE-2024-54451
A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers (authenticated as system administrators) to inject a... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 28, 2024
-
9.4
CRITICALCVE-2024-54450
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that ... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 28, 2024
-
7.5
HIGHCVE-2024-39025
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 31, 2024
-
5.3
MEDIUMCVE-2024-12991
A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as problematic. This vulnerability affects unknown code of the file /home-order. The manipulation of the argument orderStatus with the input... Read more
Affected Products :- Published: Dec. 27, 2024
- Modified: Dec. 27, 2024