Latest CVE Feed
-
9.8
CRITICALCVE-2024-34399
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer suppor... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-40568
Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
8.6
HIGHCVE-2023-47105
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.... Read more
Affected Products :- Published: Sep. 18, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46049
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46048
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
7.5
HIGHCVE-2024-46047
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46046
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2024-46044
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.... Read more
- Published: Sep. 13, 2024
- Modified: Sep. 20, 2024
-
5.9
MEDIUMCVE-2024-45040
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with com... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
6.2
MEDIUMCVE-2024-45039
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark ... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
8.8
HIGHCVE-2024-7717
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more
Affected Products : wp_events_manager- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4100
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been block... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
7.8
HIGHCVE-2024-38210
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-38209
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUM- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.3
MEDIUMCVE-2024-38207
Microsoft Edge (HTML-based) Memory Corruption Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 23, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-1384
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and... Read more
Affected Products : auxinportfolio- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-3679
The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.001. This makes it possible for unauthenticated attackers to view limited information from password protect... Read more
Affected Products : wp_seo_plugin- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-1056
The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally allow script and iframe tags in posts in all versions u... Read more
Affected Products : funnel_builder- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-8302
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to ... Read more
- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024