Latest CVE Feed
-
7.5
HIGHCVE-2024-5803
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
7.5
HIGHCVE-2024-47614
async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability i... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
3.5
LOWCVE-2024-47612
DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-fai... Read more
Affected Products : datadump- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
8.0
HIGHCVE-2024-8733
A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.3
CRITICALCVE-2024-41988
TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.1
CRITICALCVE-2024-35293
An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code v... Read more
Affected Products : october- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9441
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality ... Read more
Affected Products : emerge_e3_firmware- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2024-42504
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
5.8
MEDIUMCVE-2024-47762
Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. ... Read more
- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
8.6
HIGHCVE-2024-41987
The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative pr... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
4.5
MEDIUMCVE-2024-21530
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-9100
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.... Read more
Affected Products : manageengine_analytics_plus- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
6.9
MEDIUMCVE-2024-9174
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI... Read more
Affected Products : hubshare- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-35294
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-9266
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.... Read more
Affected Products : express- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-41925
The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-45186
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
3.3
LOWCVE-2024-0125
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A successful exploit of this vulnerability might lead to a ... Read more
Affected Products : cuda_toolkit- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
9.3
CRITICALCVE-2024-45367
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024