Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2024-41864

    Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim... Read more

    Affected Products : substance_3d_designer
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    CVE-2024-41863

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more

    Affected Products : substance_3d_sampler
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    CVE-2024-41862

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more

    Affected Products : substance_3d_sampler
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    CVE-2024-41861

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more

    Affected Products : substance_3d_sampler
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    CVE-2024-41860

    Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more

    Affected Products : substance_3d_sampler
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 7.8

    HIGH
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 7.8

    HIGH
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 7.8

    HIGH
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.1

    MEDIUM
    CVE-2024-41613

    A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.... Read more

    Affected Products : symphony_cms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 5.3

    MEDIUM
    CVE-2024-41941

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without... Read more

    Affected Products : sinec_nms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 9.4

    CRITICAL
    CVE-2024-41940

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privilege... Read more

    Affected Products : sinec_nms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 8.8

    HIGH
    CVE-2024-41939

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the applicatio... Read more

    Affected Products : sinec_nms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 5.5

    MEDIUM
    CVE-2024-41938

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated attacker it to delete arbitrary cert... Read more

    Affected Products : sinec_nms
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 5.4

    MEDIUM
    CVE-2024-41907

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to c... Read more

    Affected Products : sinec_traffic_analyzer
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.5

    MEDIUM
    CVE-2024-41906

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data s... Read more

    Affected Products : sinec_traffic_analyzer
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 7.6

    HIGH
    CVE-2024-41905

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get a... Read more

    Affected Products : sinec_traffic_analyzer
    • Published: Aug. 13, 2024
    • Modified: Aug. 14, 2024
  • 6.8

    MEDIUM
    CVE-2024-21806

    Improper conditions check in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an authenticated user to potentially enable denial of service via local access.... Read more

    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 8.1

    HIGH
    CVE-2023-49144

    Out of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access.... Read more

    Affected Products :
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
  • 6.7

    MEDIUM
    CVE-2024-21766

    Uncontrolled search path for some Intel(R) oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more

    Affected Products : oneapi_math_kernel_library
    • Published: Aug. 14, 2024
    • Modified: Aug. 14, 2024
Showing 20 of 290013 Results