Latest CVE Feed
-
6.1
MEDIUMCVE-2024-44797
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.... Read more
Affected Products : gazelle- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
6.5
MEDIUMCVE-2024-8165
A vulnerability, which was classified as problematic, was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function exportZip of the file /admin/file_manager/export. The manipulation of the argument path leads to path ... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.8
HIGHCVE-2024-8164
A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/Controllers/FileManagerController.php. The manipulation ... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.1
HIGHCVE-2024-8163
A vulnerability classified as critical was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this vulnerability is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files leads... Read more
Affected Products : beikeshop- Published: Aug. 26, 2024
- Modified: Sep. 06, 2024
-
8.3
HIGHCVE-2024-7570
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.... Read more
Affected Products : neurons_for_itsm- Published: Aug. 13, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-7569
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.... Read more
Affected Products : neurons_for_itsm- Published: Aug. 13, 2024
- Modified: Sep. 06, 2024
-
4.3
MEDIUMCVE-2024-37898
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having del... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024
-
9.9
CRITICALCVE-2024-37901
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchS... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024
-
9.0
CRITICALCVE-2024-41947
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of th... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024
-
7.5
HIGHCVE-2024-23499
Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 28.3 may allow an unauthenticated user to potentially enable denial of service via network access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
7.8
HIGHCVE-2024-23907
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
7.8
HIGHCVE-2024-23909
Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : field_programmable_gate_array_software_development_kit_for_opencl- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
9.3
CRITICALCVE-2024-23981
Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
9.3
CRITICALCVE-2024-24986
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
8.5
HIGHCVE-2024-25576
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access.... Read more
Affected Products : agilex_7_fpga_firmware- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
8.5
HIGHCVE-2024-26022
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : aptio_v_uefi_firmware_integrator_tools- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
7.8
HIGHCVE-2024-26025
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
7.8
HIGHCVE-2024-26027
Uncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : simics_package_manager- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
5.6
MEDIUMCVE-2024-27461
Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : memory_and_storage_tool_gui- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
7.8
HIGHCVE-2024-28046
Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : graphics_performance_analyzers- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024