Latest CVE Feed
-
3.9
LOWCVE-2024-45617
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
6.4
MEDIUMCVE-2024-8276
The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg block in all versions up to, and including, 1.4.4 due to insufficie... Read more
Affected Products : wpzoom_portfolio- Published: Aug. 31, 2024
- Modified: Sep. 13, 2024
-
9.1
CRITICALCVE-2024-7856
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'f... Read more
Affected Products : mp3_audio_player_for_music\,_radio_\&_podcast- Published: Aug. 29, 2024
- Modified: Sep. 13, 2024
-
8.1
HIGHCVE-2021-22509
A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue affects NetIQ Advance Authentication before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
7.2
HIGHCVE-2021-38120
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version b... Read more
Affected Products : netiq_advanced_authentication netiq_advance_authentication netiq_advance_authentication- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
8.8
HIGHCVE-2021-38121
Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance Authentication versions before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
8.2
HIGHCVE-2021-38122
A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
6.3
MEDIUMCVE-2021-22529
A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-43758
Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open ... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
5.5
MEDIUMCVE-2024-45111
Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this iss... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
9.9
CRITICALCVE-2021-22530
A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This is... Read more
- Published: Aug. 28, 2024
- Modified: Sep. 13, 2024
-
5.5
MEDIUMCVE-2024-43759
Illustrator versions 28.6, 27.9.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a DoS con... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-43756
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that ... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-43760
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vict... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-45108
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vict... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-45109
Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vict... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
9.8
CRITICALCVE-2024-41874
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing c... Read more
Affected Products : coldfusion- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.5
HIGHCVE-2024-45113
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the integrity of the ap... Read more
Affected Products : coldfusion- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-39380
After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024
-
7.8
HIGHCVE-2024-39381
After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 13, 2024