Latest CVE Feed
-
4.3
MEDIUMCVE-2024-42504
A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
4.5
MEDIUMCVE-2024-21530
Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
6.9
MEDIUMCVE-2024-9174
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI... Read more
Affected Products : hubshare- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9441
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality ... Read more
Affected Products : emerge_e3_firmware- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
4.7
MEDIUMCVE-2024-45962
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code v... Read more
Affected Products : october- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
5.8
MEDIUMCVE-2024-47762
Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. ... Read more
- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
8.6
HIGHCVE-2024-41987
The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative pr... Read more
Affected Products :- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
6.5
MEDIUMCVE-2024-9100
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.... Read more
Affected Products : manageengine_analytics_plus- Published: Oct. 03, 2024
- Modified: Oct. 04, 2024
-
5.1
MEDIUMCVE-2024-9279
A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of the component User Center. The manipulation of the argument User Nickname leads to cross site scripting... Read more
Affected Products : mee-admin- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
5.9
MEDIUMCVE-2024-43986
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: through 1.0.9.... Read more
Affected Products : ecab_taxi_booking_manager- Published: Aug. 29, 2024
- Modified: Oct. 04, 2024
-
4.8
MEDIUMCVE-2024-3944
The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm... Read more
Affected Products : wp_to_do- Published: Aug. 29, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-5857
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions... Read more
- Published: Aug. 29, 2024
- Modified: Oct. 04, 2024
-
5.4
MEDIUMCVE-2024-5987
The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and includi... Read more
Affected Products : wp_accessibility_helper- Published: Aug. 29, 2024
- Modified: Oct. 04, 2024
-
7.1
HIGHCVE-2024-7341
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijac... Read more
- Published: Sep. 09, 2024
- Modified: Oct. 04, 2024
-
8.6
HIGHCVE-2024-20467
A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to im... Read more
Affected Products : ios_xe- Published: Sep. 25, 2024
- Modified: Oct. 03, 2024
-
8.6
HIGHCVE-2024-20480
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of se... Read more
Affected Products : ios_xe- Published: Sep. 25, 2024
- Modified: Oct. 03, 2024
-
9.8
CRITICALCVE-2024-7732
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.... Read more
Affected Products : dr.id_attendance_system- Published: Aug. 14, 2024
- Modified: Oct. 03, 2024
-
7.8
HIGHCVE-2024-44967
In the Linux kernel, the following vulnerability has been resolved: drm/mgag200: Bind I2C lifetime to DRM device Managed cleanup with devm_add_action_or_reset() will release the I2C adapter when the underlying Linux device goes away. But the connector s... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Oct. 03, 2024
-
5.4
MEDIUMCVE-2024-8536
The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored... Read more
Affected Products : ultimate_blocks- Published: Sep. 30, 2024
- Modified: Oct. 03, 2024
-
8.8
HIGHCVE-2024-23923
Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploi... Read more
- Published: Sep. 28, 2024
- Modified: Oct. 03, 2024