Latest CVE Feed
-
2.4
LOWCVE-2024-4211
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been disc... Read more
Affected Products : application_automation_tools- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
8.0
HIGHCVE-2024-4189
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.... Read more
Affected Products : application_automation_tools- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
8.0
HIGHCVE-2024-4184
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.... Read more
Affected Products : application_automation_tools- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
5.4
MEDIUMCVE-2024-46606
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.... Read more
Affected Products : piwigo- Published: Oct. 16, 2024
- Modified: May. 22, 2025
-
6.1
MEDIUMCVE-2024-46605
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.... Read more
Affected Products : piwigo- Published: Oct. 16, 2024
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2024-45072
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
5.5
MEDIUMCVE-2024-45071
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
8.8
HIGHCVE-2024-38814
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execut... Read more
Affected Products : vmware_hcx- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
6.1
MEDIUMCVE-2024-20512
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface... Read more
Affected Products : unified_contact_center_management_portal- Published: Oct. 16, 2024
- Modified: Aug. 04, 2025
-
7.1
HIGHCVE-2024-20463
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to modify the configuration or reboot an affected device. This vulnerability is due to the H... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2024-20462
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability i... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
6.0
MEDIUMCVE-2024-20461
A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high privileges to execute arbitrary commands as the root user. This vulnerability exists because CLI input is n... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 22, 2024
-
6.1
MEDIUMCVE-2024-20460
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user. This vulnerability ... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
7.2
HIGHCVE-2024-20459
A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with high privileges to execute arbitrary commands as the root user on the underlyi... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 22, 2024
-
8.2
HIGHCVE-2024-20458
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulne... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 22, 2024
-
7.1
HIGHCVE-2024-20421
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affec... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2024-20420
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an Admin user. This vulnerability is due to incorrect ... Read more
- Published: Oct. 16, 2024
- Modified: Oct. 31, 2024
-
6.3
MEDIUMCVE-2024-20280
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weak... Read more
- Published: Oct. 16, 2024
- Modified: Jun. 18, 2025
-
6.1
MEDIUMCVE-2024-10033
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, inj... Read more
- Published: Oct. 16, 2024
- Modified: Mar. 26, 2025
-
5.3
MEDIUMCVE-2023-32266
Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. This issue affects Applic... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024