Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-10668

    There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is c... Read more

    Affected Products : windows nearby quick_share
    • Published: Nov. 07, 2024
    • Modified: Jul. 23, 2025
  • 4.3

    MEDIUM
    CVE-2024-9926

    The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form... Read more

    Affected Products : jetpack
    • Published: Nov. 07, 2024
    • Modified: May. 28, 2025
  • 7.5

    HIGH
    CVE-2024-43440

    A flaw was found in moodle. A local file may include risks when restoring block backups.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-43438

    A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: Aug. 05, 2025
  • 7.2

    HIGH
    CVE-2024-43436

    A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: Aug. 05, 2025
  • 8.1

    HIGH
    CVE-2024-43434

    The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-43431

    A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.7

    HIGH
    CVE-2024-43428

    To address a cache poisoning risk in Moodle, additional validation for local storage was required.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 7.5

    HIGH
    CVE-2024-43426

    A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: Aug. 05, 2025
  • 8.1

    HIGH
    CVE-2024-43425

    A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.... Read more

    Affected Products : moodle
    • Published: Nov. 07, 2024
    • Modified: May. 01, 2025
  • 6.4

    MEDIUM
    CVE-2024-8442

    The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficien... Read more

    Affected Products : prime_slider
    • Published: Nov. 07, 2024
    • Modified: Feb. 05, 2025
  • 8.0

    HIGH
    CVE-2024-24914

    Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.... Read more

    • Published: Nov. 07, 2024
    • Modified: Aug. 26, 2025
  • 8.6

    HIGH
    CVE-2024-10526

    Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselve... Read more

    Affected Products : velociraptor
    • Published: Nov. 07, 2024
    • Modified: Nov. 08, 2024
  • 9.1

    CRITICAL
    CVE-2024-51504

    When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address dete... Read more

    Affected Products : zookeeper
    • Published: Nov. 07, 2024
    • Modified: Jun. 24, 2025
  • 5.5

    MEDIUM
    CVE-2024-50172

    In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 13, 2024
  • 5.5

    MEDIUM
    CVE-2024-50171

    In the Linux kernel, the following vulnerability has been resolved: net: systemport: fix potential memory leak in bcm_sysport_xmit() The bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb in case of dma_map_single() fails, add dev_kfree_skb() t... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 13, 2024
  • 5.5

    MEDIUM
    CVE-2024-50170

    In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 13, 2024
  • 5.5

    MEDIUM
    CVE-2024-50169

    In the Linux kernel, the following vulnerability has been resolved: vsock: Update rx_bytes on read_skb() Make sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt() calls are balanced (i.e. virtio_vsock_sock::rx_bytes doesn't lie) after vs... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 22, 2024
  • 5.5

    MEDIUM
    CVE-2024-50168

    In the Linux kernel, the following vulnerability has been resolved: net/sun3_82586: fix potential memory leak in sun3_82586_send_packet() The sun3_82586_send_packet() returns NETDEV_TX_OK without freeing skb in case of skb->len being too long, add dev_k... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 13, 2024
  • 5.5

    MEDIUM
    CVE-2024-50167

    In the Linux kernel, the following vulnerability has been resolved: be2net: fix potential memory leak in be_xmit() The be_xmit() returns NETDEV_TX_OK without freeing skb in case of be_xmit_enqueue() fails, add dev_kfree_skb_any() to fix it.... Read more

    Affected Products : linux_kernel
    • Published: Nov. 07, 2024
    • Modified: Nov. 13, 2024
Showing 20 of 293617 Results