Latest CVE Feed
-
9.8
CRITICALCVE-2024-29401
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.... Read more
Affected Products : xzs-mysql- Published: Mar. 26, 2024
- Modified: Sep. 19, 2025
-
5.3
MEDIUMCVE-2024-32210
The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.... Read more
Affected Products : lomag_warehouse_management- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
5.5
MEDIUMCVE-2024-32211
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.... Read more
Affected Products : lomag_warehouse_management- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
5.5
MEDIUMCVE-2023-52661
In the Linux kernel, the following vulnerability has been resolved: drm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe() If clk_get_sys(..., "pll_d2_out0") fails, the clk_get_sys() call must be undone. Add the missi... Read more
Affected Products : linux_kernel- Published: May. 17, 2024
- Modified: Sep. 19, 2025
-
5.4
MEDIUMCVE-2024-52312
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.... Read more
Affected Products : data.all- Published: Nov. 09, 2024
- Modified: Sep. 19, 2025
-
8.1
HIGHCVE-2024-32212
SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.... Read more
Affected Products : lomag_warehouse_management- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
5.3
MEDIUMCVE-2024-52313
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.al... Read more
Affected Products : data.all- Published: Nov. 09, 2024
- Modified: Sep. 19, 2025
-
6.9
MEDIUMCVE-2024-52314
A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for particular operations that interact with c... Read more
Affected Products : data.all- Published: Nov. 09, 2024
- Modified: Sep. 19, 2025
-
6.3
MEDIUMCVE-2024-52311
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.... Read more
Affected Products : data.all- Published: Nov. 09, 2024
- Modified: Sep. 19, 2025
-
5.3
MEDIUMCVE-2024-10953
An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.... Read more
Affected Products : data.all- Published: Nov. 09, 2024
- Modified: Sep. 19, 2025
-
7.1
HIGHCVE-2024-33429
Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.... Read more
Affected Products : phiola- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
8.6
HIGHCVE-2024-12744
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30... Read more
Affected Products : amazon_web_services_redshift_java_database_connectivity_driver- Published: Dec. 24, 2024
- Modified: Sep. 19, 2025
-
8.8
HIGHCVE-2024-33430
An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.... Read more
Affected Products : phiola- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
7.8
HIGHCVE-2025-8893
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the cont... Read more
Affected Products : autocad advance_steel autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d revit +1 more products- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-8894
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context... Read more
Affected Products : autocad advance_steel autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_plant_3d revit +1 more products- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-33431
An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.... Read more
Affected Products : phiola- Published: May. 01, 2024
- Modified: Sep. 19, 2025
-
8.8
HIGHCVE-2024-4215
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within... Read more
- Published: May. 02, 2024
- Modified: Sep. 19, 2025
-
7.4
HIGHCVE-2024-4216
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.... Read more
- Published: May. 02, 2024
- Modified: Sep. 19, 2025
-
5.3
MEDIUMCVE-2024-34408
Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.... Read more
- Published: May. 03, 2024
- Modified: Sep. 19, 2025
-
9.0
CRITICALCVE-2024-0087
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, ... Read more
- Published: May. 14, 2024
- Modified: Sep. 19, 2025