Latest CVE Feed
-
7.6
HIGHCVE-2024-46639
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-43989
Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid allows Server Side Request Forgery.This issue affects Justified Image Grid: from n/a through 4.6.1.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-47210
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.... Read more
Affected Products :- Published: Sep. 21, 2024
- Modified: Sep. 26, 2024
-
6.6
MEDIUMCVE-2024-45229
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connect... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
4.7
MEDIUMCVE-2024-8903
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.... Read more
Affected Products : cyber_protect_cloud_agent- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
0.0
NACVE-2022-48945
In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle page fault for address: ffffc9000a3b1000 #PF: supervisor write access in kernel mode #PF:... Read more
Affected Products : linux_kernel- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2024-47337
Missing Authorization vulnerability in Stuart Wilson Joy Of Text Lite.This issue affects Joy Of Text Lite: from n/a through 2.3.1.... Read more
Affected Products : joy_of_text_lite- Published: Sep. 26, 2024
- Modified: Sep. 26, 2024
-
8.6
HIGHCVE-2024-30128
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.... Read more
Affected Products : nomad_server_on_domino- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
5.3
MEDIUMCVE-2024-43990
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-42506
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-7479
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows sys... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
7.1
HIGHCVE-2024-43959
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themepoints Testimonials allows Reflected XSS.This issue affects Testimonials: from n/a through 3.0.8.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-8175
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.... Read more
- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
8.7
HIGHCVE-2024-8497
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.... Read more
Affected Products : ts-550_evo_firmware- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2024-9141
Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaScript code into the body of a chat message. This manipulation occurs when the chat content is intercepted and altered, leading to the ex... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-42505
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.3
CRITICALCVE-2024-4657
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: before 30840.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
6.1
MEDIUMCVE-2024-20496
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a ... Read more
Affected Products : sd-wan_vedge_router- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-46936
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-42507
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024