Latest CVE Feed
-
5.5
MEDIUMCVE-2024-53129
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop: Fix a dereferenced before check warning The 'state' can't be NULL, we should check crtc_state. Fix warning: drivers/gpu/drm/rockchip/rockchip_drm_vop.c:1096 vop_plan... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: Dec. 14, 2024
-
5.5
MEDIUMCVE-2024-53128
In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers When CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the object_is_on_stack() function may produce incorrec... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: May. 02, 2025
-
5.5
MEDIUMCVE-2024-53127
In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" The commit 8396c793ffdf ("mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K") increased the max_req_size, ev... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: Dec. 14, 2024
-
7.8
HIGHCVE-2024-53126
In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_open_pf_bar() and snet_open_vf_bar() a string later passed to pcim_iomap_regions() is placed on the stack. Neither pcim_iomap_regions() n... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: Dec. 11, 2024
-
5.4
MEDIUMCVE-2024-40745
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.... Read more
Affected Products : convert_forms- Published: Dec. 04, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-40744
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.... Read more
Affected Products : convert_forms- Published: Dec. 04, 2024
- Modified: Jun. 04, 2025
-
2.3
LOWCVE-2024-12056
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requ... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
5.3
MEDIUMCVE-2024-7488
Improper Input Validation vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks.This issue affects Online Ordering System: 8.2.1. NOTE: Vulnerability fixed in version 8.2.2 and does not exist before 8.2.1.... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 05, 2024
-
0.0
NACVE-2024-53125
In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def Range propagation must not affect subreg_def marks, otherwise the following example is rewritten by verifier incorrectly when BPF_F_TEST... Read more
Affected Products : linux_kernel- Published: Dec. 04, 2024
- Modified: Dec. 19, 2024
-
8.8
HIGHCVE-2024-51465
IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more
- Published: Dec. 04, 2024
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2024-12138
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to d... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
6.4
MEDIUMCVE-2024-11935
The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
6.4
MEDIUMCVE-2024-8962
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possi... Read more
Affected Products : wpbits_addons_for_elementor_page_builder- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
8.1
HIGHCVE-2024-8894
Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause... Read more
Affected Products : comos- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
5.3
MEDIUMCVE-2024-54158
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 30, 2025
-
6.5
MEDIUMCVE-2024-54157
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 30, 2025
-
6.5
MEDIUMCVE-2024-54156
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 30, 2025
-
5.3
MEDIUMCVE-2024-54155
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2024-54154
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 31, 2025
-
6.5
MEDIUMCVE-2024-54153
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter... Read more
Affected Products : youtrack- Published: Dec. 04, 2024
- Modified: Jan. 31, 2025