Latest CVE Feed
-
6.1
MEDIUMCVE-2022-23861
Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution ... Read more
Affected Products : safeq- Published: Oct. 22, 2024
- Modified: Nov. 01, 2024
-
9.0
HIGHCVE-2024-10283
A vulnerability, which was classified as critical, has been found in Tenda RX9 and RX9 Pro 22.03.02.20. Affected by this issue is the function sub_4337EC of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buf... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-10280
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument ... Read more
Affected Products : ac6_firmware ac9_firmware ac15_firmware ac18_firmware ac10_firmware ac7_firmware ac1206_firmware ac8_firmware ac500_firmware ac10u_firmware +10 more products- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
9.0
HIGHCVE-2024-10281
A vulnerability classified as critical has been found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected is the function sub_42EEE0 of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
9.0
HIGHCVE-2024-10282
A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-base... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
7.7
HIGHCVE-2024-48735
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is disputed by the vendor because these... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-48138
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-50428
Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.... Read more
Affected Products : multi_step_form- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50454
Missing Authorization vulnerability in The SEO Guys at SEOPress SEOPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through 8.1.1.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50422
Missing Authorization vulnerability in Cloudways Breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through 2.1.14.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-48206
A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2024-50423
Missing Authorization vulnerability in Templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through 3.1.5.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2019-25219
Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
4.8
MEDIUMCVE-2024-48461
Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-50421
Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through 3.8.6.... Read more
Affected Products : woocommerce_pdf_invoices\&_packing_slips- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-50424
Missing Authorization vulnerability in Templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through 3.1.5.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-50425
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Veribo, Roland Murg WP Booking System.This issue affects WP Booking System: from n/a through 2.0.19.10.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
5.5
MEDIUMCVE-2024-50354
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal... Read more
Affected Products : gnark-crypto- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.6
MEDIUMCVE-2024-50344
I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
6.3
MEDIUMCVE-2024-50347
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This API is used in ... Read more
Affected Products : laravel- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024