Latest CVE Feed
-
6.4
MEDIUMCVE-2024-47079
Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for the broader project. The remote hardware module of the firmware does not h... Read more
- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
6.5
MEDIUMCVE-2024-47818
Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitiz... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
6.5
MEDIUMCVE-2024-21533
All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL sch... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
7.3
HIGHCVE-2024-21532
All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe e... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.1
MEDIUMCVE-2024-47817
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a ... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-9292
The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-45873
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
5.5
MEDIUMCVE-2024-31228
Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COM... Read more
Affected Products : redis- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
7.3
HIGHCVE-2024-47610
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page and exe... Read more
Affected Products : inventree- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
4.0
MEDIUMCVE-2024-34670
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
8.3
HIGHCVE-2024-47555
Missing Authentication - User & System Configuration... Read more
Affected Products : freeflow_core- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
7.0
HIGHCVE-2024-31449
Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists ... Read more
Affected Products : redis- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
5.1
MEDIUMCVE-2024-47973
In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
6.1
MEDIUMCVE-2024-9207
The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated att... Read more
Affected Products : buddypress_docs- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-8433
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and ou... Read more
- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.3
MEDIUMCVE-2022-4534
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
5.3
MEDIUMCVE-2024-9622
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transitio... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
7.5
HIGHCVE-2024-25885
An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-41798
A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass th... Read more
Affected Products : sentron_pac3200_firmware- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-8964
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possib... Read more
Affected Products : sirv- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024