Latest CVE Feed
-
5.5
MEDIUMCVE-2024-46761
In the Linux kernel, the following vulnerability has been resolved: pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv The hotplug driver for powerpc (pci/hotplug/pnv_php.c) causes a kernel crash when we try to hot-unplug/disable the PCIe switch/b... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 23, 2024
-
7.8
HIGHCVE-2024-30073
Windows Security Zone Mapping Security Feature Bypass Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +10 more products- Published: Sep. 10, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-28170
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
4.7
MEDIUMCVE-2024-46679
In the Linux kernel, the following vulnerability has been resolved: ethtool: check device is present when getting link settings A sysfs reader can race with a device reset or removal, attempting to read device state when the device is not actually prese... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-32666
NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-46680
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix random crash seen while removing driver This fixes the random kernel crash seen while removing the driver, when running the load/unload test over multiple iter... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-32940
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-46678
In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called insi... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-33848
Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.5
MEDIUMCVE-2024-46676
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Add poll mod list filling check In case of im_protocols value is 1 and tm_protocols value is 0 this combination successfully passes the check 'if (!im_protocols && !tm_proto... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-44056
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through 3.3.2.... Read more
Affected Products : mantra- Published: Sep. 15, 2024
- Modified: Sep. 23, 2024
-
7.8
HIGHCVE-2024-34153
Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-44057
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Nirvana allows Stored XSS.This issue affects Nirvana: from n/a through 1.6.3.... Read more
Affected Products : nirvana- Published: Sep. 15, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-44058
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through 2.4.1.... Read more
Affected Products : parabola- Published: Sep. 15, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-44054
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Fluida allows Stored XSS.This issue affects Fluida: from n/a through 1.8.8.... Read more
Affected Products : fluida- Published: Sep. 15, 2024
- Modified: Sep. 23, 2024
-
7.8
HIGHCVE-2024-34543
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.7
MEDIUMCVE-2024-36261
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.7
MEDIUMCVE-2024-36247
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
5.7
MEDIUMCVE-2024-34545
Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products : raid_web_console- Published: Sep. 16, 2024
- Modified: Sep. 23, 2024
-
6.5
MEDIUMCVE-2024-42483
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared resource for al... Read more
Affected Products : esp-now- Published: Sep. 12, 2024
- Modified: Sep. 23, 2024