Latest CVE Feed
-
9.8
CRITICALCVE-2024-10964
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible... Read more
Affected Products : neuron- Published: Nov. 07, 2024
- Modified: Nov. 26, 2024
-
4.8
MEDIUMCVE-2024-8378
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.... Read more
Affected Products : safe_svg- Published: Nov. 07, 2024
- Modified: May. 17, 2025
-
7.4
HIGHCVE-2024-10963
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue pose... Read more
Affected Products : enterprise_linux openshift_container_platform international_components_for_unicode- Published: Nov. 07, 2024
- Modified: Feb. 06, 2025
-
7.5
HIGHCVE-2024-10668
There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability lies in the fact that when a Payload Transfer frame of type FILE is sent to Quick Share, the file that is c... Read more
- Published: Nov. 07, 2024
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2024-9926
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form... Read more
Affected Products : jetpack- Published: Nov. 07, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-43440
A flaw was found in moodle. A local file may include risks when restoring block backups.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43438
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
7.2
HIGHCVE-2024-43436
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
8.1
HIGHCVE-2024-43434
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43431
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.7
HIGHCVE-2024-43428
To address a cache poisoning risk in Moodle, additional validation for local storage was required.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-43426
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
8.1
HIGHCVE-2024-43425
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: May. 01, 2025
-
6.4
MEDIUMCVE-2024-8442
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficien... Read more
Affected Products : prime_slider- Published: Nov. 07, 2024
- Modified: Feb. 05, 2025
-
8.0
HIGHCVE-2024-24914
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.... Read more
- Published: Nov. 07, 2024
- Modified: Aug. 26, 2025
-
8.6
HIGHCVE-2024-10526
Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselve... Read more
Affected Products : velociraptor- Published: Nov. 07, 2024
- Modified: Nov. 08, 2024
-
9.1
CRITICALCVE-2024-51504
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address dete... Read more
Affected Products : zookeeper- Published: Nov. 07, 2024
- Modified: Jun. 24, 2025
-
5.5
MEDIUMCVE-2024-50172
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50171
In the Linux kernel, the following vulnerability has been resolved: net: systemport: fix potential memory leak in bcm_sysport_xmit() The bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb in case of dma_map_single() fails, add dev_kfree_skb() t... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-50170
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2024
- Modified: Nov. 13, 2024