Latest CVE Feed
-
9.1
CRITICALCVE-2023-48082
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.... Read more
Affected Products : nagios_xi- Published: Oct. 14, 2024
- Modified: Jul. 10, 2025
-
5.3
MEDIUMCVE-2024-48795
An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
5.9
MEDIUMCVE-2024-48793
An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 15, 2024
-
7.5
HIGHCVE-2024-48792
An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 15, 2024
-
7.5
HIGHCVE-2024-48791
An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 19, 2025
-
5.3
MEDIUMCVE-2024-48790
An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-48789
An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 19, 2025
-
7.5
HIGHCVE-2024-47831
Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which could ... Read more
Affected Products : next.js- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
6.1
MEDIUMCVE-2024-47826
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". It wo... Read more
Affected Products : elabftw- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-47767
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not ha... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-47766
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the conte... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
5.7
MEDIUMCVE-2024-46988
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with infor... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.8
MEDIUMCVE-2024-46980
Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact lin... Read more
Affected Products : tuleap- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-46528
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources with... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Aug. 28, 2025
-
7.5
HIGHCVE-2024-48799
An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 24, 2025
-
7.5
HIGHCVE-2024-48798
An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 24, 2025
-
7.5
HIGHCVE-2024-48797
An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 25, 2025
-
7.5
HIGHCVE-2024-48796
An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2024-48168
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.... Read more
- Published: Oct. 14, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-46535
Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.... Read more
Affected Products : jepaas- Published: Oct. 14, 2024
- Modified: Jul. 03, 2025