Latest CVE Feed
-
4.3
MEDIUMCVE-2024-39410
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. ... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-39412
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
5.5
MEDIUMCVE-2024-41867
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Sep. 13, 2024
- Modified: Oct. 16, 2024
-
7.2
HIGHCVE-2024-9381
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47011
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47010
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-45148
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauth... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47009
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47008
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47007
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-8630
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 16, 2024
-
6.7
MEDIUMCVE-2024-37983
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 +7 more products- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2023-7260
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.... Read more
Affected Products : cx-e_voice- Published: Aug. 22, 2024
- Modified: Oct. 16, 2024
-
4.4
MEDIUMCVE-2024-7489
The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color parameters in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output e... Read more
Affected Products : forms_for_mailchimp_by_optin_cat- Published: Oct. 12, 2024
- Modified: Oct. 16, 2024
-
5.9
MEDIUMCVE-2024-48793
An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 15, 2024
-
7.5
HIGHCVE-2024-48771
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
7.5
HIGHCVE-2024-48768
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.5
MEDIUMCVE-2024-46215
A vulnerability was discovered in KM08-708H-v1.1, There is a buffer overflow in the sub_445BDC() function within the /usr/sbin/goahead program; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-44807
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.5
MEDIUMCVE-2024-44415
A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.... Read more
Affected Products : di-8200_firmware- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024