Latest CVE Feed
-
10.0
CRITICALCVE-2024-51791
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through 2.8.0.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
8.0
HIGHCVE-2024-45827
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may exec... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
6.1
MEDIUMCVE-2024-9357
The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.12.04 due to insufficient input sanitization and output escaping. This makes it possible for unauthe... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-51572
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Peter Shaw LH QR Codes allows Stored XSS.This issue affects LH QR Codes: from n/a through 1.06.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
4.6
MEDIUMCVE-2024-29075
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
5.1
MEDIUMCVE-2024-52288
libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced into an active str... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.1
CRITICALCVE-2024-51747
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `... Read more
Affected Products : kanboard- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
3.5
LOWCVE-2024-47799
Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain information o... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
8.8
HIGHCVE-2024-47590
An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in th... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
3.5
LOWCVE-2024-47587
Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
5.8
MEDIUMCVE-2024-23983
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.... Read more
Affected Products : pingaccess- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
5.3
MEDIUMCVE-2024-47586
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and r... Read more
Affected Products : netweaver_application_server_abap- Published: Nov. 12, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-47295
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versions, see the inf... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Nov. 11, 2024
-
8.9
HIGHCVE-2024-7059
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.... Read more
Affected Products : security_center- Published: Nov. 05, 2024
- Modified: Nov. 09, 2024
-
7.8
HIGH- Published: Oct. 08, 2024
- Modified: Nov. 08, 2024
-
8.8
HIGHCVE-2024-44021
Missing Authorization vulnerability in Truepush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Truepush: from n/a through 1.0.8.... Read more
Affected Products : truepush- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50109
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null ptr dereference in raid10_size() In raid10_run() if raid10_set_queue_limits() succeed, the return value is set to zero, and if following procedures failed raid10_run... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-6762
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50108
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too Stuart Hayhurst has found that both at bootup and fullscreen VA-API video is leading to black screens for around 1 second and ke... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50107
In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses Commit 50c6dbdfd16e ("x86/ioremap: Improve iounmap() address range checks") introduces a WARN when adrre... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024