Latest CVE Feed
-
6.5
MEDIUMCVE-2024-11060
A vulnerability classified as critical has been found in Jinher Network Collaborative Management Platform 金和数字化智能办公平台 1.0. Affected is an unknown function of the file /C6/JHSoft.Web.AcceptAip/AcceptShow.aspx/. The manipulation of the argument id leads to ... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-11059
A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulatio... Read more
Affected Products : free_download_online_shopping_system- Published: Nov. 11, 2024
- Modified: Aug. 28, 2025
-
0.0
NACVE-2023-40457
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: ... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2020-10370
Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Jan. 27, 2025
-
7.2
HIGHCVE-2024-11058
A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads ... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 13, 2024
-
7.5
HIGHCVE-2021-41737
In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L: abM-^Q;" and "process = route(3333333333333333333,2,1,2,3,1) : *;" leads to stack consumption.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 19, 2024
-
9.1
CRITICALCVE-2021-35473
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handle... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 19, 2024
-
5.5
MEDIUMCVE-2020-10369
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
3.5
LOWCVE-2020-10368
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
5.5
MEDIUMCVE-2020-10367
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
7.8
HIGHCVE-2024-46956
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
5.5
MEDIUMCVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.4
HIGHCVE-2024-46954
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.... Read more
Affected Products : ghostscript- Published: Nov. 10, 2024
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2024-46953
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.4
HIGHCVE-2024-46952
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-46951
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-46613
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_sp... Read more
Affected Products : weechat- Published: Nov. 10, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11057
A vulnerability has been found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /removeBranchResult.php. The manipulation of the argument ID/Name leads to sql in... Read more
Affected Products : hospital_appointment_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.0
HIGHCVE-2024-11056
A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is poss... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-11055
A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to s... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024