Latest CVE Feed
-
6.1
MEDIUMCVE-2024-10046
The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.5. This makes it pos... Read more
Affected Products : persian_woocommerce_sms- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.9
MEDIUMCVE-2024-54138
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequa... Read more
Affected Products : nugetgallery- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
7.5
HIGHCVE-2024-44856
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44855
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44854
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44853
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-44852
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-41650
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41649
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41648
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41647
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41646
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41645
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41644
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-38927
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl ... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38926
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38925
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl ... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38924
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl l... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38923
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl o... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38922
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024