Latest CVE Feed
-
7.5
HIGHCVE-2024-44853
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-44852
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-41650
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41649
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41648
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41647
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41646
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41645
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41644
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-38927
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl ... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38926
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38925
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl ... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38924
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl l... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38923
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl o... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38922
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-38921
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl ... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
5.3
MEDIUMCVE-2024-7875
Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpScreenResolutionWidth parameter manipulation in a form sent to an endpoint /TotalAgility/Kofax/BrowserDevice/ScanFront.aspx... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
5.3
MEDIUMCVE-2024-7874
Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to endpoints "/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx" and "/T... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
6.1
MEDIUMCVE-2024-12326
Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scripting. This was done by storing the MIME type of a file and preventing the browser preview for MIME type image... Read more
Affected Products : jirafeau- Published: Dec. 06, 2024
- Modified: Aug. 05, 2025
-
4.4
MEDIUMCVE-2024-0139
NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of this vulnerability might lead to denial of service.... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024