Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2024-54140

    sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 5.4

    MEDIUM
    CVE-2024-53457

    A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.... Read more

    Affected Products : librenms
    • Published: Dec. 05, 2024
    • Modified: Apr. 07, 2025
  • 6.7

    MEDIUM
    CVE-2017-13308

    In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction ... Read more

    Affected Products : android
    • Published: Dec. 05, 2024
    • Modified: Dec. 19, 2024
  • 7.5

    HIGH
    CVE-2024-53523

    JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 8.4

    HIGH
    CVE-2024-53589

    GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Mar. 14, 2025
  • 9.8

    CRITICAL
    CVE-2024-53442

    whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 9.8

    CRITICAL
    CVE-2024-41579

    DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 8.7

    HIGH
    CVE-2024-11148

    In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.... Read more

    Affected Products : openbsd openbsd
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 5.0

    MEDIUM
    CVE-2024-10933

    In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.... Read more

    Affected Products : openbsd openbsd
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 9.1

    CRITICAL
    CVE-2023-50913

    Oxide control plane software before 5 allows SSRF.... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 9.8

    CRITICAL
    CVE-2023-48010

    STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access t... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 6.5

    MEDIUM
    CVE-2024-12235

    A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 8.5

    HIGH
    CVE-2024-12130

    An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor c... Read more

    Affected Products : arena arena_simulation
    • Published: Dec. 05, 2024
    • Modified: Dec. 17, 2024
  • 8.5

    HIGH
    CVE-2024-11158

    An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor... Read more

    Affected Products : arena arena_simulation
    • Published: Dec. 05, 2024
    • Modified: Apr. 18, 2025
  • 8.5

    HIGH
    CVE-2024-11156

    An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerabi... Read more

    Affected Products : arena arena_simulation
    • Published: Dec. 05, 2024
    • Modified: Dec. 17, 2024
  • 8.5

    HIGH
    CVE-2024-11155

    A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this ... Read more

    Affected Products : arena arena_simulation
    • Published: Dec. 05, 2024
    • Modified: Apr. 14, 2025
  • 5.7

    MEDIUM
    CVE-2024-54128

    Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which ca... Read more

    Affected Products : directus
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 5.5

    MEDIUM
    CVE-2024-53846

    OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP st... Read more

    Affected Products : otp
    • Published: Dec. 05, 2024
    • Modified: Dec. 05, 2024
  • 7.5

    HIGH
    CVE-2024-53490

    Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.... Read more

    Affected Products :
    • Published: Dec. 05, 2024
    • Modified: Dec. 11, 2024
  • 9.8

    CRITICAL
    CVE-2024-12234

    A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-customer-detailed.php. The manipulation of the argument name leads to sql injectio... Read more

    Affected Products : beauty_parlour_management_system
    • Published: Dec. 05, 2024
    • Modified: Dec. 10, 2024
Showing 20 of 291891 Results