Latest CVE Feed
-
9.8
CRITICALCVE-2024-52410
Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector allows Object Injection.This issue affects Referrer Detector: from n/a through 4.2.1.0.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52406
Unrestricted Upload of File with Dangerous Type vulnerability in Wibergs Web CSV to html allows Upload a Web Shell to a Web Server.This issue affects CSV to html: from n/a through 3.04.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52400
Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: from n/a through 1.01.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.1
CRITICALCVE-2024-52398
Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI.This issue affects CDI: from n/a through 5.5.3.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.3
MEDIUMCVE-2024-10262
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before runn... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.4
HIGHCVE-2024-43704
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.... Read more
Affected Products : ddk- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-52918
Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2020-3431
A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripti... Read more
Affected Products : small_business_rv_series_router_firmware- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-10786
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated a... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.7
HIGHCVE-2024-0793
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.... Read more
Affected Products : kubernetes- Published: Nov. 17, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-10884
The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.0. This makes... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-11092
The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-10875
The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_Arg without appropriate escaping on the URL in all versions up to, and including, 1.6.58. This makes it possible for unauthenticated at... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10017
The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10147
The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2020-26063
A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper ... Read more
Affected Products : unified_computing_system- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2024-52941
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This c... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2020-25720
A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. Th... Read more
Affected Products : samba- Published: Nov. 17, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2024-11085
The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subsc... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50324
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024