Latest CVE Feed
-
7.8
HIGHCVE-2024-47134
Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Softwar... Read more
- Published: Oct. 03, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-9975
A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulation leads to unrestricted upload. The attack may be launc... Read more
Affected Products : drag_and_drop_image_upload- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-9976
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation of the argument text leads to sql injection. It is pos... Read more
Affected Products : pharmacy_management_system- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
5.5
MEDIUMCVE-2024-39379
Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of th... Read more
- Published: Jul. 31, 2024
- Modified: Oct. 16, 2024
-
6.8
MEDIUMCVE-2024-39406
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An admin attacker cou... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-39408
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changeson behalf of a user. T... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-39409
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. ... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-39410
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass security features and perform minor integrity changes on behalf of a user. ... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-39412
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass securi... Read more
- Published: Aug. 14, 2024
- Modified: Oct. 16, 2024
-
5.5
MEDIUMCVE-2024-41867
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Sep. 13, 2024
- Modified: Oct. 16, 2024
-
7.2
HIGHCVE-2024-9381
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47011
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47010
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-45148
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauth... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47009
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47008
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2024-47007
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-8630
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 16, 2024
-
6.7
MEDIUMCVE-2024-37983
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 +7 more products- Published: Oct. 08, 2024
- Modified: Oct. 16, 2024
-
7.5
HIGHCVE-2023-7260
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.... Read more
Affected Products : cx-e_voice- Published: Aug. 22, 2024
- Modified: Oct. 16, 2024