Latest CVE Feed
-
5.5
MEDIUMCVE-2024-46728
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check index for aux_rd_interval before using aux_rd_interval has size of 7 and should be checked. This fixes 3 OVERRUN and 1 INTEGER_OVERFLOW issues reported by Coveri... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
7.1
HIGHCVE-2024-46731
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix the Out-of-bounds read warning using index i - 1U may beyond element index for mc_data[] when i = 0.... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2024-45614
Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on prox... Read more
Affected Products : puma- Published: Sep. 19, 2024
- Modified: Sep. 26, 2024
-
5.5
MEDIUMCVE-2024-46732
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Assign linear_pitch_alignment even for VM [Description] Assign linear_pitch_alignment so we don't cause a divide by 0 error in VM environments... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
5.5
MEDIUMCVE-2024-46755
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id() mwifiex_get_priv_by_id() returns the priv pointer corresponding to the bss_num and bss_type, but without checking if... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
5.5
MEDIUMCVE-2024-46765
In the Linux kernel, the following vulnerability has been resolved: ice: protect XDP configuration with a mutex The main threat to data consistency in ice_xdp() is a possible asynchronous PF reset. It can be triggered by a user or by TX timeout handler.... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
7.8
HIGHCVE-2024-46786
In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not deleted when the fsc... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
7.8
HIGHCVE-2024-46746
In the Linux kernel, the following vulnerability has been resolved: HID: amd_sfh: free driver_data after destroying hid device HID driver callbacks aren't called anymore once hid_destroy_device() has been called. Hence, hid driver_data should be freed o... Read more
Affected Products : linux_kernel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-22303
Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-43491
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit thes... Read more
- Actively Exploited
- Published: Sep. 10, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2024-41434
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between '... Read more
Affected Products : tidb- Published: Sep. 03, 2024
- Modified: Sep. 25, 2024
-
9.8
CRITICALCVE-2024-41433
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reprodu... Read more
Affected Products : tidb- Published: Sep. 03, 2024
- Modified: Sep. 25, 2024
-
6.5
MEDIUMCVE-2024-44001
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.982.... Read more
Affected Products : royal_elementor_addons- Published: Sep. 18, 2024
- Modified: Sep. 25, 2024
-
7.1
HIGHCVE-2024-44002
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25.... Read more
Affected Products : team_showcase- Published: Sep. 18, 2024
- Modified: Sep. 25, 2024
-
7.1
HIGHCVE-2024-44003
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites allows Reflected XSS.This issue affects Spice Starter Sites: from n/a through 1.2.5.... Read more
Affected Products : spice_starter_sites- Published: Sep. 18, 2024
- Modified: Sep. 25, 2024
-
6.5
MEDIUMCVE-2024-43995
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sonalsinha21 Posterity allows Stored XSS.This issue affects Posterity: from n/a through 3.6.... Read more
Affected Products : posterity- Published: Sep. 18, 2024
- Modified: Sep. 25, 2024
-
8.8
HIGHCVE-2024-8253
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This mak... Read more
Affected Products : post_grid- Published: Sep. 11, 2024
- Modified: Sep. 25, 2024
-
4.8
MEDIUMCVE-2024-3899
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.... Read more
Affected Products : envira_gallery- Published: Sep. 11, 2024
- Modified: Sep. 25, 2024
-
4.8
MEDIUMCVE-2024-7716
The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
- Published: Sep. 11, 2024
- Modified: Sep. 25, 2024
-
6.4
MEDIUMCVE-2024-8440
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to ins... Read more
Affected Products : essential_addons_for_elementor- Published: Sep. 11, 2024
- Modified: Sep. 25, 2024