Latest CVE Feed
-
7.5
HIGHCVE-2024-10668
There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is c... Read more
- Published: Nov. 07, 2024
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2024-9926
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form... Read more
Affected Products : jetpack- Published: Nov. 07, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-43440
A flaw was found in moodle. A local file may include risks when restoring block backups.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43438
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
7.2
HIGHCVE-2024-43436
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
8.1
HIGHCVE-2024-43434
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43431
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.7
HIGHCVE-2024-43428
To address a cache poisoning risk in Moodle, additional validation for local storage was required.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43426
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
8.1
HIGHCVE-2024-43425
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
6.4
MEDIUMCVE-2024-8442
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficien... Read more
Affected Products : prime_slider- Published: Nov. 07, 2024
- Modified: Feb. 05, 2025
-
8.0
HIGHCVE-2024-24914
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.... Read more
- Published: Nov. 07, 2024
- Modified: Aug. 26, 2025
-
8.6
HIGHCVE-2024-10526
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselve... Read more
Affected Products : velociraptor- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-51504
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address dete... Read more
Affected Products : zookeeper- Published: Nov. 07, 2024
- Modified: Jun. 24, 2025
-
5.5
MEDIUMCVE-2024-50172
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50171
In the Linux kernel, the following vulnerability has been resolved: net: systemport: fix potential memory leak in bcm_sysport_xmit() The bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb in case of dma_map_single() fails, add dev_kfree_skb() t... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50170
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50169
In the Linux kernel, the following vulnerability has been resolved: vsock: Update rx_bytes on read_skb() Make sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt() calls are balanced (i.e. virtio_vsock_sock::rx_bytes doesn't lie) after vs... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 22, 2024
-
5.5
MEDIUMCVE-2024-50168
In the Linux kernel, the following vulnerability has been resolved: net/sun3_82586: fix potential memory leak in sun3_82586_send_packet() The sun3_82586_send_packet() returns NETDEV_TX_OK without freeing skb in case of skb->len being too long, add dev_k... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50167
In the Linux kernel, the following vulnerability has been resolved: be2net: fix potential memory leak in be_xmit() The be_xmit() returns NETDEV_TX_OK without freeing skb in case of be_xmit_enqueue() fails, add dev_kfree_skb_any() to fix it.... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024