Latest CVE Feed
-
6.4
MEDIUMCVE-2024-9449
The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products : auto_iframe- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-9451
The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible f... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.4
MEDIUMCVE-2024-47816
ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the centr... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
8.4
HIGHCVE-2024-9412
An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
6.0
MEDIUMCVE-2024-47815
IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the `editinc... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.0
MEDIUMCVE-2024-47812
ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS payloads in the messages for dates, and thus XSS anyone w... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.6
HIGHCVE-2024-47334
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow for WordPress allows SQL Injection.This issue affects Zoho Flow for WordPress: from n/a through 2.7.1.... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.7
MEDIUMCVE-2024-38818
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
8.2
HIGHCVE-2024-9468
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-38815
VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.7
MEDIUMCVE-2024-38817
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.5
MEDIUMCVE-2024-47763
Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was co... Read more
Affected Products : wasmtime- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network... Read more
Affected Products : prestashop- Published: Aug. 12, 2024
- Modified: Oct. 09, 2024
-
7.2
HIGHCVE-2024-20470
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit ... Read more
Affected Products : small_business_rv_series_router_firmware rv340_dual_wan_gigabit_vpn_router_firmware rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware rv345_dual_wan_gigabit_vpn_router_firmware rv345p_dual_wan_gigabit_poe_vpn_router_firmware rv340_dual_wan_gigabit_vpn_router rv340w_dual_wan_gigabit_wireless-ac_vpn_router rv345_dual_wan_gigabit_vpn_router rv345p_dual_wan_gigabit_poe_vpn_router- Published: Oct. 02, 2024
- Modified: Oct. 09, 2024
-
5.5
MEDIUMCVE-2024-46834
In the Linux kernel, the following vulnerability has been resolved: ethtool: fail closed if we can't get max channel used in indirection tables Commit 0d1b7d6c9274 ("bnxt: fix crashes when reducing ring count with active RSS contexts") proves that allow... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024
-
7.8
HIGHCVE-2024-46833
In the Linux kernel, the following vulnerability has been resolved: net: hns3: void array out of bound when loop tnl_num When query reg inf of SSU, it loops tnl_num times. However, tnl_num comes from hardware and the length of array is a fixed value. To... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024
-
5.5
MEDIUMCVE-2024-46832
In the Linux kernel, the following vulnerability has been resolved: MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed This avoids warning: [ 0.118053] BUG: sleeping function called from invalid context at kernel/locking/mutex.c... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024
-
7.8
HIGHCVE-2024-46836
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: validate endpoint index for ast udc We should verify the bound of the array to assure that host may not manipulate the index to point past endpoint array. Foun... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024
-
5.5
MEDIUMCVE-2024-46837
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Restrict high priorities on group_create We were allowing any users to create a high priority group without any permission checks. As a result, this was allowing possible d... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024
-
5.5
MEDIUMCVE-2024-46838
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: don't BUG_ON() if khugepaged yanks our page table Since khugepaged was changed to allow retracting page tables in file mappings without holding the mmap lock, these BUG_ON(... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 09, 2024