Latest CVE Feed
-
9.4
CRITICALCVE-2024-47062
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furt... Read more
Affected Products : navidrome- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
7.6
HIGHCVE-2024-46639
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
4.7
MEDIUMCVE-2024-8903
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.... Read more
Affected Products : cyber_protect_cloud_agent- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-45489
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This ins... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-39342
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys ar... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.8
MEDIUMCVE-2024-23933
Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not requ... Read more
Affected Products : xav-ax5500_firmware- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.9
CRITICALCVE-2024-9014
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.... Read more
Affected Products : pgadmin- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
0.0
NACVE-2022-48945
In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle page fault for address: ffffc9000a3b1000 #PF: supervisor write access in kernel mode #PF:... Read more
Affected Products : linux_kernel- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
4.8
MEDIUMCVE-2024-45793
Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/credentials, GET /v1/credentials/, GET /v1/archive/credent... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
7.2
HIGHCVE-2024-40442
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-40441
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs param... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-7835
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS.This issue affects Ferry Reservation System: before 240805-002.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-47210
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.... Read more
Affected Products :- Published: Sep. 21, 2024
- Modified: Sep. 26, 2024
-
6.1
MEDIUMCVE-2024-42697
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-23934
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. User interaction is required to exp... Read more
Affected Products : xav-ax5500_firmware- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-44540
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-34331
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.... Read more
Affected Products : parallels_desktop- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2023-46948
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.... Read more
Affected Products : t24- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.5
MEDIUMCVE-2024-44048
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows PHP Local File Inclusion.This issue affects Product Carousel Slider & Grid Ultimate for Wo... Read more
Affected Products : product_carousel_slider_\&_grid_ultimate_for_woocommerce- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.3
HIGHCVE-2024-47061
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` pr... Read more
Affected Products : plate- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024