Latest CVE Feed
-
8.6
HIGHCVE-2023-47105
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.7
HIGHCVE-2024-7737
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products : 3dexperience- Published: Sep. 19, 2024
- Modified: Sep. 20, 2024
-
7.5
HIGHCVE-2024-37406
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-40568
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
5.0
MEDIUMCVE-2024-46990
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `1... Read more
Affected Products : directus- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.7
HIGHCVE-2024-7736
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products : 3dexperience- Published: Sep. 19, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-44542
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.... Read more
Affected Products : todesk- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46049
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46048
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
7.5
HIGHCVE-2024-46047
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46046
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46044
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
5.9
MEDIUMCVE-2024-45040
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with com... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
6.2
MEDIUMCVE-2024-45039
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark ... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-7717
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more
Affected Products : wp_events_manager- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4100
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been block... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4536
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restr... Read more
Affected Products : ip-vault-wp-firewall- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
7.8
HIGHCVE-2024-38210
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-38209
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUM- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024