Latest CVE Feed
-
8.6
HIGHCVE-2024-52007
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTY... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
8.7
HIGHCVE-2024-52004
MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-52002
Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer to the linked GHSA for the complete list. This issue has been addressed in version 3.2.0 a... Read more
Affected Products : itop- Published: Nov. 08, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2024-52001
Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known worka... Read more
Affected Products : itop- Published: Nov. 08, 2024
- Modified: Jan. 07, 2025
-
8.1
HIGHCVE-2024-52000
Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been add... Read more
Affected Products : itop- Published: Nov. 08, 2024
- Modified: Jan. 07, 2025
-
5.5
MEDIUMCVE-2024-35427
vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-35426
vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-48073
sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 18, 2024
-
5.5
MEDIUMCVE-2024-35425
vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-35424
vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
7.8
HIGHCVE-2024-35423
vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
7.8
HIGHCVE-2024-35422
vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-35421
vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c.... Read more
Affected Products : vmir- Published: Nov. 08, 2024
- Modified: Jun. 05, 2025
-
6.2
MEDIUMCVE-2024-35420
wac commit 385e1 was discovered to contain a heap overflow.... Read more
Affected Products : wac- Published: Nov. 08, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2024-35419
wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.... Read more
Affected Products : wac- Published: Nov. 08, 2024
- Modified: Jun. 17, 2025
-
6.2
MEDIUMCVE-2024-35418
wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.... Read more
Affected Products : wac- Published: Nov. 08, 2024
- Modified: Jun. 17, 2025
-
6.2
MEDIUMCVE-2024-35410
wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.... Read more
Affected Products : wac- Published: Nov. 08, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2024-27532
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 19, 2024
-
8.4
HIGHCVE-2024-27530
wasm3 139076a contains a Use-After-Free in ForEachModule.... Read more
Affected Products : wasm3- Published: Nov. 08, 2024
- Modified: Jun. 24, 2025
-
8.4
HIGHCVE-2024-27529
wasm3 139076a contains memory leaks in Read_utf8.... Read more
Affected Products : wasm3- Published: Nov. 08, 2024
- Modified: Jun. 24, 2025