Latest CVE Feed
-
7.5
HIGHCVE-2024-47072
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input strea... Read more
- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
8.7
HIGHCVE-2024-8810
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vu... Read more
Affected Products : enterprise_server- Published: Nov. 07, 2024
- Modified: Aug. 27, 2025
-
6.1
MEDIUMCVE-2024-51434
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-50766
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.... Read more
- Published: Nov. 07, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-49524
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DO... Read more
- Published: Nov. 07, 2024
- Modified: Dec. 02, 2024
-
5.4
MEDIUMCVE-2024-49523
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Nov. 07, 2024
- Modified: Dec. 02, 2024
-
8.1
HIGHCVE-2024-46961
The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-46960
The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component.... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
6.2
MEDIUMCVE-2024-36064
The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.nll.cb.dia... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-36063
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivi... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
4.0
MEDIUMCVE-2024-36062
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.andr... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Feb. 10, 2025
-
6.5
MEDIUMCVE-2024-10824
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organization ... Read more
Affected Products : enterprise_server- Published: Nov. 07, 2024
- Modified: Aug. 27, 2025
-
6.1
MEDIUMCVE-2024-50599
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject... Read more
Affected Products : zimbra_collaboration_suite- Published: Nov. 07, 2024
- Modified: Jun. 17, 2025
-
7.7
HIGHCVE-2024-10975
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed... Read more
Affected Products : nomad- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-10007
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exploitation of this vulnerability requires Enterprise Administrator access to ... Read more
Affected Products : enterprise_server- Published: Nov. 07, 2024
- Modified: Aug. 27, 2025
-
6.2
MEDIUMCVE-2019-20472
An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for a... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
4.6
MEDIUMCVE-2019-20469
An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the audior directory. An attacker who has physical access can retrieve all audio files by c... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
5.3
MEDIUMCVE-2019-20462
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view p... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2019-20461
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. Based upon the reverse engineering, no password or usern... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2019-20460
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request is from a legitimate source. In addition, CSRF attacks can be used to send text... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024