Latest CVE Feed
-
7.6
HIGHCVE-2024-47334
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow for WordPress allows SQL Injection.This issue affects Zoho Flow for WordPress: from n/a through 2.7.1.... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
8.5
HIGHCVE-2024-9575
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5.... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Jan. 09, 2025
-
5.5
MEDIUMCVE-2024-47420
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.5
MEDIUMCVE-2024-47419
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47418
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47417
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47416
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47415
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47414
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47413
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47412
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47411
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-47410
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.5
MEDIUMCVE-2024-45145
Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitatio... Read more
Affected Products : lightroom- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45150
Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45146
Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicio... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
5.5
MEDIUMCVE-2024-20787
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this... Read more
Affected Products : substance_3d_painter- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
6.4
MEDIUMCVE-2024-9451
The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible f... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-9449
The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products : auto_iframe- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-39586
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024