Latest CVE Feed
-
5.5
MEDIUMCVE-2020-10369
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
3.5
LOWCVE-2020-10368
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
5.5
MEDIUMCVE-2020-10367
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.... Read more
Affected Products :- Published: Nov. 10, 2024
- Modified: Nov. 26, 2024
-
7.8
HIGHCVE-2024-46956
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
5.5
MEDIUMCVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.4
HIGHCVE-2024-46954
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.... Read more
Affected Products : ghostscript- Published: Nov. 10, 2024
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2024-46953
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
8.4
HIGHCVE-2024-46952
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.8
HIGHCVE-2024-46951
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-46613
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_sp... Read more
Affected Products : weechat- Published: Nov. 10, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11057
A vulnerability has been found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /removeBranchResult.php. The manipulation of the argument ID/Name leads to sql in... Read more
Affected Products : hospital_appointment_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.0
HIGHCVE-2024-11056
A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is poss... Read more
- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-11055
A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to s... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
7.3
HIGHCVE-2024-10958
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an acti... Read more
Affected Products : wp_photo_album_plus- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.1
MEDIUMCVE-2024-10265
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1... Read more
Affected Products : form_maker- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51576
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZA AMP Img Shortcode allows Stored XSS.This issue affects AMP Img Shortcode: from n/a through 1.0.1.... Read more
Affected Products : amp_img_shortcode- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51578
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Luca Paggetti 3D Presentation allows Stored XSS.This issue affects 3D Presentation: from n/a through 1.0.... Read more
Affected Products : 3d_presentation- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51577
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Camunda Services GmbH bpmn.Io allows Stored XSS.This issue affects bpmn.Io: from n/a through 1.0.... Read more
Affected Products : bpmn.io- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
9.8
CRITICALCVE-2024-11054
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload... Read more
Affected Products : simple_music_cloud_community_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024
-
6.5
MEDIUMCVE-2024-51584
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Anas Edreesi Marquee Elementor with Posts allows DOM-Based XSS.This issue affects Marquee Elementor with Posts: from n/a through 1.2.0.... Read more
Affected Products : marquee_elementor_with_posts- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024