Latest CVE Feed
-
5.3
MEDIUMCVE-2024-9405
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located ... Read more
Affected Products : pluckcms- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-9274
The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticat... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-9118
The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products : qs_dark_mode- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9108
The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticate... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-8728
The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attacke... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.9
MEDIUMCVE-2024-9174
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI... Read more
Affected Products : hubshare- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8159
Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-9333
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-9266
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.... Read more
Affected Products : express- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
8.6
HIGHCVE-2024-41987
The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative pr... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
8.8
HIGHCVE-2024-8885
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-35294
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-9100
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.... Read more
Affected Products : manageengine_analytics_plus- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code v... Read more
Affected Products : october- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2024-42504
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
5.8
MEDIUMCVE-2024-47762
Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. ... Read more
- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
4.5
MEDIUMCVE-2024-21530
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.3
CRITICALCVE-2024-45367
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9441
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality ... Read more
Affected Products : emerge_e3_firmware- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-9423
Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024