Latest CVE Feed
-
7.1
HIGHCVE-2024-38746
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories) allows Path Traversal, Server Side Request Forgery.This issue affects MakeStories (for Google Web Stories... Read more
Affected Products : makestories_\(for_google_web_stories\)- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.8
CRITICALCVE-2024-39619
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more
Affected Products : listingpro- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.0
HIGHCVE-2024-7331
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
8.1
HIGHCVE-2024-6873
It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available withi... Read more
Affected Products : clickhouse- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
8.5
HIGHCVE-2024-7358
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to cre... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
7.3
HIGHCVE-2024-6242
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute C... Read more
Affected Products : 1756-en4tr_firmware- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
9.6
CRITICALCVE-2024-41961
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft ... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
7.5
HIGHCVE-2024-41255
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
9.8
CRITICALCVE-2024-6695
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.... Read more
Affected Products : profile_builder- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
8.3
HIGHCVE-2024-42381
os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-s... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
7.1
HIGHCVE-2024-41253
goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
7.3
HIGHCVE-2022-4001
An authentication bypass vulnerability could allow an attacker to access API functions without authentication.... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
4.4
MEDIUMCVE-2024-41951
Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding languages are visible in code. The Problem was patched in 0.2.4.... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
4.7
MEDIUMCVE-2024-39694
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as ... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
8.5
HIGHCVE-2024-7324
A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the component BPL Handler. The manipulation leads to uncontro... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
5.4
MEDIUMCVE-2024-39318
The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authentica... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
9.8
CRITICALCVE-2024-41660
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory ove... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
7.5
HIGHCVE-2024-41950
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
9.4
CRITICALCVE-2024-7205
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.... Read more
Affected Products : ewelink- Published: Jul. 31, 2024
- Modified: Jul. 31, 2024
-
6.5
MEDIUMCVE-2024-7135
The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it... Read more
Affected Products : tainacan- Published: Jul. 31, 2024
- Modified: Jul. 31, 2024