Latest CVE Feed
-
8.1
HIGHCVE-2024-8642
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for t... Read more
Affected Products : eclipse_dataspace_components- Published: Sep. 11, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-45388
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new simulation views from the contents of a user-specified file. This feature can ... Read more
Affected Products : hoverfly- Published: Sep. 02, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-41869
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-45112
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource i... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-3305
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.... Read more
Affected Products : soliclub- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-3306
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.... Read more
Affected Products : soliclub- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-5546
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 19, 2024
-
8.7
HIGHCVE-2024-7269
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to c... Read more
Affected Products : esp_hr_management- Published: Aug. 28, 2024
- Modified: Sep. 19, 2024
-
8.7
HIGHCVE-2024-6077
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.... Read more
Affected Products : compactlogix_5380_firmware controllogix_5580_firmware compactlogix_5480_firmware guardlogix_5580_firmware compactlogix_5380 compact_guardlogix_5380_sil_2_firmware compact_guardlogix_5380_sil_2 compact_guardlogix_5380_sil_3_firmware compact_guardlogix_5380_sil_3 compactlogix_5480 +6 more products- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-27114
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is ... Read more
Affected Products : soplanning- Published: Sep. 11, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUMCVE-2021-22503
Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
9.1
CRITICALCVE-2021-22533
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
7.6
HIGHCVE-2021-22532
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.... Read more
Affected Products : edirectory- Published: Sep. 12, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-20440
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by send... Read more
Affected Products : smart_license_utility- Published: Sep. 04, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46701
In the Linux kernel, the following vulnerability has been resolved: libfs: fix infinite directory reads for offset dir After we switch tmpfs dir operations from simple_dir_operations to simple_offset_dir_operations, every rename happened will fill new d... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-8108
The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46702
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Mark XDomain as unplugged when router is removed I noticed that when we do discrete host router NVM upgrade and it gets hot-removed from the PCIe side as a result of NVM fi... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46703
In the Linux kernel, the following vulnerability has been resolved: Revert "serial: 8250_omap: Set the console genpd always on if no console suspend" This reverts commit 68e6939ea9ec3d6579eadeab16060339cdeaf940. Kevin reported that this causes a crash ... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
4.7
MEDIUMCVE-2024-46704
In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix spruious data race in __flush_work() When flushing a work item for cancellation, __flush_work() knows that it exclusively owns the work item through its PENDING bit. 1348... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024
-
5.5
MEDIUMCVE-2024-46705
In the Linux kernel, the following vulnerability has been resolved: drm/xe: reset mmio mappings with devm Set our various mmio mappings to NULL. This should make it easier to catch something rogue trying to mess with mmio after device removal. For examp... Read more
Affected Products : linux_kernel- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024