Latest CVE Feed
-
9.8
CRITICALCVE-2024-45874
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-45873
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
4.4
MEDIUMCVE-2024-47974
Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 31, 2024
-
5.1
MEDIUMCVE-2024-47973
In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
4.4
MEDIUMCVE-2024-47967
Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2024-47772
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This issue only affects sites with CSP disabled. This problem ... Read more
Affected Products : discourse- Published: Oct. 07, 2024
- Modified: Oct. 19, 2024
-
7.3
HIGHCVE-2024-47610
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page and exe... Read more
Affected Products : inventree- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
6.5
MEDIUMCVE-2024-45919
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to una... Read more
Affected Products : solvait- Published: Oct. 07, 2024
- Modified: Jul. 03, 2025
-
5.3
MEDIUMCVE-2024-45297
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are... Read more
Affected Products : discourse- Published: Oct. 07, 2024
- Modified: Oct. 19, 2024
-
8.8
HIGHCVE-2024-45291
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedIm... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 16, 2024
-
7.7
HIGHCVE-2024-45290
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the XLSX file, PhpSpreadsheet retrieves the image size and type by r... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 16, 2024
-
7.1
HIGHCVE-2024-45060
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading t... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 17, 2024
-
8.2
HIGHCVE-2024-45051
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the l... Read more
Affected Products : discourse- Published: Oct. 07, 2024
- Modified: Oct. 19, 2024
-
7.5
HIGHCVE-2024-43789
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in t... Read more
Affected Products : discourse- Published: Oct. 07, 2024
- Modified: Oct. 19, 2024
-
8.2
HIGHCVE-2024-43365
Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected ... Read more
Affected Products : cacti- Published: Oct. 07, 2024
- Modified: Oct. 16, 2024
-
8.2
HIGHCVE-2024-43364
Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, the said title parameter is stored in the database and reflected back to user in index.p... Read more
Affected Products : cacti- Published: Oct. 07, 2024
- Modified: Oct. 17, 2024
-
7.2
HIGHCVE-2024-43363
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need ... Read more
Affected Products : cacti- Published: Oct. 07, 2024
- Modified: Oct. 17, 2024
-
7.3
HIGHCVE-2024-43362
Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function... Read more
Affected Products : cacti- Published: Oct. 07, 2024
- Modified: Oct. 17, 2024
-
6.7
MEDIUMCVE-2024-47976
Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Mar. 13, 2025
-
4.0
MEDIUMCVE-2024-47972
Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Nov. 06, 2024