Latest CVE Feed
-
10.0
CRITICALCVE-2024-48967
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make u... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
10.0
CRITICALCVE-2024-48966
The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipu... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2024-40579
Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the hostname parameter.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
5.3
MEDIUMCVE-2024-39707
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3,... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 27, 2024
-
9.8
CRITICALCVE-2024-31695
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Dec. 03, 2024
-
9.3
CRITICALCVE-2024-9834
Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.3
CRITICALCVE-2024-9832
There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to ... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
7.1
HIGHCVE-2024-51687
Cross-Site Request Forgery (CSRF) vulnerability in Platform.Ly Platform.Ly Official allows Stored XSS.This issue affects Platform.Ly Official: from n/a through 1.1.3.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
7.1
HIGHCVE-2024-51684
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO allows Stored XSS.This issue affects W3P SEO: from n/a before 1.8.6.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
7.1
HIGHCVE-2024-51688
Cross-Site Request Forgery (CSRF) vulnerability in FraudLabs Pro FraudLabs Pro SMS Verification allows Stored XSS.This issue affects FraudLabs Pro SMS Verification: from n/a through 1.10.1.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2024-49025
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability... Read more
Affected Products : edge_chromium- Published: Nov. 14, 2024
- Modified: Jan. 07, 2025
-
7.8
HIGHCVE-2024-10397
A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.... Read more
Affected Products : openafs- Published: Nov. 14, 2024
- Modified: Aug. 05, 2025
-
7.1
HIGHCVE-2024-10396
An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client Fet... Read more
Affected Products : openafs- Published: Nov. 14, 2024
- Modified: Aug. 06, 2025
-
8.4
HIGHCVE-2024-10394
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.... Read more
Affected Products : openafs- Published: Nov. 14, 2024
- Modified: Aug. 07, 2025
-
9.9
CRITICALCVE-2024-52370
Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support – WordPress Help Desk allows Upload a Web Shell to a Web Server.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.1.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.9
CRITICALCVE-2024-52369
Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access Inc. KBucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: from n/a through 4.1.6.... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
7.5
HIGHCVE-2024-3760
In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volum... Read more
Affected Products : lunary- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.3
HIGHCVE-2024-5125
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulnerability allows attackers to embed malicious JavaScript ... Read more
- Published: Nov. 14, 2024
- Modified: Jul. 07, 2025
-
6.9
MEDIUMCVE-2024-52524
Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, ... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2024-52396
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in realmag777 WOLF allows Path Traversal.This issue affects WOLF: from n/a through 1.0.8.3.... Read more
Affected Products : wolf_-_wordpress_posts_bulk_editor_and_products_manager_professional- Published: Nov. 14, 2024
- Modified: Mar. 12, 2025