Latest CVE Feed
-
6.5
MEDIUMCVE-2024-48898
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.... Read more
Affected Products : moodle- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
6.5
MEDIUMCVE-2024-48897
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.... Read more
Affected Products : moodle- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
4.3
MEDIUMCVE-2024-48896
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format ... Read more
Affected Products : moodle- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.6
CRITICALCVE-2024-11319
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3.... Read more
Affected Products : django_cms- Published: Nov. 18, 2024
- Modified: Aug. 26, 2025
-
6.1
MEDIUMCVE-2024-11023
Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manip... Read more
Affected Products : firebase_javascript_sdk- Published: Nov. 18, 2024
- Modified: Jul. 23, 2025
-
7.5
HIGHCVE-2024-42392
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.3
MEDIUMCVE-2024-42391
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.3
MEDIUMCVE-2024-42390
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.3
MEDIUMCVE-2024-42389
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.3
MEDIUMCVE-2024-42388
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.3
MEDIUMCVE-2024-42387
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
8.2
HIGHCVE-2024-42386
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
7.0
HIGHCVE-2024-42385
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
7.5
HIGHCVE-2024-42384
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Jan. 13, 2025
-
9.8
CRITICALCVE-2024-42383
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.... Read more
Affected Products : mongoose- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
7.1
HIGHCVE-2024-41974
A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025
-
8.1
HIGHCVE-2024-41973
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025
-
6.5
MEDIUMCVE-2024-41972
A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025
-
8.1
HIGHCVE-2024-41971
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025
-
5.7
MEDIUMCVE-2024-41970
A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Aug. 27, 2025