Latest CVE Feed
-
9.8
CRITICALCVE-2024-34331
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.... Read more
Affected Products : parallels_desktop- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.3
CRITICALCVE-2024-7735
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection.This issue affects Ferry Reservation System: before 240805-002.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
3.7
LOWCVE-2024-45453
Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maintenance Redirect: from n/a through 2.0.1.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-39342
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys ar... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.3
HIGHCVE-2024-47061
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` pr... Read more
Affected Products : plate- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-40441
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs param... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
7.2
HIGHCVE-2024-40442
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
4.8
MEDIUMCVE-2024-45793
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/credentials, GET /v1/credentials/, GET /v1/archive/credent... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
4.7
MEDIUMCVE-2024-8903
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.... Read more
Affected Products : cyber_protect_cloud_agent- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-43989
Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid allows Server Side Request Forgery.This issue affects Justified Image Grid: from n/a through 4.6.1.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-47210
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.... Read more
Affected Products :- Published: Sep. 21, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-45489
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This ins... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-7479
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows sys... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
8.7
HIGHCVE-2024-8497
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.... Read more
Affected Products : ts-550_evo_firmware- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
3.8
LOWCVE-2024-45599
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly b... Read more
Affected Products : cursor- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
5.5
MEDIUMCVE-2024-9169
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
Affected Products : litespeed_cache- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2024-9141
Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the ex... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-8175
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.... Read more
- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.3
CRITICALCVE-2024-4657
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: before 30840.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-42505
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024