Latest CVE Feed
-
8.1
HIGHCVE-2024-7601
Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentica... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.1
HIGHCVE-2024-7600
Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exp... Read more
Affected Products : unified_secops_platform- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-7329
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It... Read more
Affected Products : youdiancms- Published: Jul. 31, 2024
- Modified: Aug. 23, 2024
-
6.1
MEDIUMCVE-2024-43407
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS attack by exploiting a flaw in the GeSHi syntax highligh... Read more
Affected Products : ckeditor- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-43371
CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote files i... Read more
Affected Products : ckan- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
8.2
HIGHCVE-2024-37311
Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2024-43105
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
8.8
HIGHCVE-2024-7559
The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for a... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
2.5
LOWCVE-2024-43785
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form AN... Read more
Affected Products :- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
0.0
NACVE-2024-43883
In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not ha... Read more
Affected Products : linux_kernel- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
7.5
HIGHCVE-2024-7986
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a ... Read more
Affected Products : thinmanager_thinserver- Published: Aug. 23, 2024
- Modified: Aug. 23, 2024
-
9.6
CRITICALCVE-2023-6452
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows administrators to generate detailed repo... Read more
Affected Products : web_security- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
5.0
MEDIUMCVE-2024-43787
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a res... Read more
Affected Products : hono- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
7.5
HIGHCVE-2024-42490
authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are /api/v3/crypto/certificatekeypairs/<uuid>/view_certificate/, /api/v3/cr... Read more
Affected Products : authentik- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.3
MEDIUMCVE-2024-32939
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visi... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
4.9
MEDIUMCVE-2024-39810
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, su... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-39836
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged email addresses, created by shared channels, to be used ... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-42782
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-42781
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
6.5
MEDIUMCVE-2024-7330
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation of the argument url leads to server-side request forgery.... Read more
Affected Products : youdiancms- Published: Aug. 01, 2024
- Modified: Aug. 23, 2024