Latest CVE Feed
-
4.8
MEDIUMCVE-2022-39996
Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
4.3
MEDIUMCVE-2024-8200
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect non... Read more
Affected Products : reviews_feed- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
4.3
MEDIUMCVE-2024-8199
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all ver... Read more
Affected Products : reviews_feed- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
8.8
HIGHCVE-2024-45264
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.... Read more
Affected Products : arfa-cms- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-44342
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-44341
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
8.8
HIGHCVE-2024-44340
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-41622
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
8.8
HIGHCVE-2024-5651
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a us... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 30, 2024
-
6.5
MEDIUMCVE-2024-3114
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the se... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 30, 2024
-
7.2
HIGHCVE-2024-6632
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.... Read more
Affected Products : filecatalyst_workflow- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-7071
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection.This issue affects Brain Low-Code: before 2... Read more
Affected Products : brain_low-code- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
7.5
HIGHCVE-2024-8182
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint... Read more
Affected Products : flowise- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
2.0
LOWCVE-2024-2502
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper ... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
6.5
MEDIUMCVE-2024-8303
A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation of the argument username leads to sql injection. It is... Read more
- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
3.7
LOWCVE-2024-43944
Incorrect Authorization vulnerability in Yassine Idrissi Maintenance & Coming Soon Redirect Animation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through 2.1.3.... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
5.5
MEDIUMCVE-2024-7537
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not required to exploit this vulnerability. ... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
7.8
HIGHCVE-2024-7538
oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
7.8
HIGHCVE-2024-7539
oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in o... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024
-
3.3
LOWCVE-2024-7540
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on... Read more
Affected Products : ofono- Published: Aug. 06, 2024
- Modified: Aug. 29, 2024