Latest CVE Feed
-
8.8
HIGHCVE-2024-9954
Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 22, 2024
-
8.1
HIGHCVE-2024-9594
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. T... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-9486
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and... Read more
Affected Products : image_builder- Published: Oct. 15, 2024
- Modified: Nov. 08, 2024
-
7.5
HIGHCVE-2024-48783
An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.... Read more
- Published: Oct. 15, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-48782
File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-48781
An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-48779
An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-48714
In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more
- Published: Oct. 15, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-48713
In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more
- Published: Oct. 15, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-48712
In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more
- Published: Oct. 15, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-48710
In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.... Read more
- Published: Oct. 15, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-48411
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.... Read more
Affected Products : online_tours_and_travels_management_system online_tours_\&_travels_management_system- Published: Oct. 15, 2024
- Modified: May. 17, 2025
-
7.5
HIGHCVE-2024-44775
An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service(DoS) via a crafted request.... Read more
Affected Products : kmqtt- Published: Oct. 15, 2024
- Modified: Sep. 04, 2025
-
8.1
HIGHCVE-2024-41311
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.... Read more
- Published: Oct. 15, 2024
- Modified: Mar. 24, 2025
-
4.9
MEDIUMCVE-2024-31955
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possess... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-49195
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair... Read more
- Published: Oct. 15, 2024
- Modified: May. 06, 2025
-
5.1
MEDIUMCVE-2024-44337
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a log... Read more
Affected Products : markdown- Published: Oct. 15, 2024
- Modified: Nov. 14, 2024
-
5.4
MEDIUMCVE-2024-21286
Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-21285
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
Affected Products : banking_liquidity_management- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
7.1
HIGHCVE-2024-21284
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
Affected Products : banking_liquidity_management- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024