Latest CVE Feed
-
5.3
MEDIUMCVE-2024-6552
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. Th... Read more
Affected Products : amelia- Published: Aug. 08, 2024
- Modified: Aug. 08, 2024
-
8.8
HIGHCVE-2024-6989
Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6994
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6991
Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7000
Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.8
HIGHCVE-2024-23456
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-7552
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulati... Read more
Affected Products : datagear- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
6.5
MEDIUMCVE-2023-28806
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.8
HIGHCVE-2024-23458
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.8
HIGHCVE-2024-23460
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.2
HIGHCVE-2024-23464
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-23483
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.... Read more
Affected Products : client_connector- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7440
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command inject... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-41616
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6988
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
7.5
HIGHCVE-2024-41990
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.... Read more
Affected Products : django- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
7.5
HIGHCVE-2024-41991
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of U... Read more
Affected Products : django- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7580
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/system.html. The manipulation of the argument uploadedFile with the input ;who... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 07, 2024
-
8.8
HIGHCVE-2024-6995
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromiu... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024
-
6.5
MEDIUMCVE-2024-7564
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required... Read more
Affected Products : unified_secops_platform- Published: Aug. 06, 2024
- Modified: Aug. 07, 2024