Latest CVE Feed
-
7.5
HIGHCVE-2024-10073
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possi... Read more
Affected Products : flair- Published: Oct. 17, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-10072
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function actionAddEncryptPolicyGroup of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument checklist... Read more
Affected Products : cdg- Published: Oct. 17, 2024
- Modified: Oct. 22, 2024
-
7.0
HIGHCVE-2024-9414
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.... Read more
Affected Products : laquis_scada- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
8.8
HIGHCVE-2024-10071
A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdateEncryptPolicyEdit of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument encryptPolicyId ... Read more
Affected Products : cdg- Published: Oct. 17, 2024
- Modified: Oct. 22, 2024
-
5.3
MEDIUMCVE-2018-25104
A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The ... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.3
MEDIUMCVE-2024-9683
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement. While the risk is relativ... Read more
Affected Products : quay- Published: Oct. 17, 2024
- Modified: Dec. 03, 2024
-
9.1
CRITICALCVE-2024-48920
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensi... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.5
MEDIUMCVE-2024-47459
Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting i... Read more
Affected Products : substance_3d_sampler- Published: Oct. 17, 2024
- Modified: Oct. 23, 2024
-
8.8
HIGHCVE-2024-10070
A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of the file /com/esafenet/policy/action/PolicyPushControlAction.java. The manipulation of the argument policyId leads to sql injection. It ... Read more
Affected Products : cdg- Published: Oct. 17, 2024
- Modified: Oct. 22, 2024
-
8.8
HIGHCVE-2024-10069
A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actionPassMainApplication of the file /com/esafenet/servlet/client/MailDecryptApplicationService.java. The manipulation of the argument id l... Read more
Affected Products : cdg- Published: Oct. 17, 2024
- Modified: Oct. 22, 2024
-
7.2
HIGHCVE-2024-6333
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Sep. 17, 2025
-
8.6
HIGHCVE-2024-49315
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through 1.0.0.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
9.8
CRITICALCVE-2005-10003
A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of a... Read more
Affected Products : xcomic- Published: Oct. 17, 2024
- Modified: Nov. 14, 2024
-
5.3
MEDIUMCVE-2024-49580
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure... Read more
Affected Products : ktor- Published: Oct. 17, 2024
- Modified: Dec. 06, 2024
-
8.1
HIGHCVE-2024-49579
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests... Read more
Affected Products : youtrack- Published: Oct. 17, 2024
- Modified: Nov. 14, 2024
-
7.1
HIGHCVE-2024-48048
Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows Stored XSS.This issue affects Wsify Widget: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.9
MEDIUMCVE-2024-48046
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Supsystic Contact Form by Supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through 1.7.28.... Read more
Affected Products : contact_form- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.4
MEDIUMCVE-2024-48037
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through 1.4.2.... Read more
Affected Products : contact_form_widget- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.5
MEDIUMCVE-2024-48036
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a thro... Read more
Affected Products : skt_blocks- Published: Oct. 17, 2024
- Modified: Jul. 10, 2025
-
7.1
HIGHCVE-2024-48032
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups ... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024