Latest CVE Feed
-
9.3
CRITICALCVE-2024-6915
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.... Read more
Affected Products : artifactory- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
3.0
LOWCVE-2024-42350
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority.... Read more
Affected Products :- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
3.9
LOWCVE-2024-41811
ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once... Read more
Affected Products :- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-6782
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.... Read more
Affected Products : calibre- Published: Aug. 06, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-40498
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php... Read more
Affected Products : online_shopping_system_advanced- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
6.0
MEDIUMCVE-2024-41820
Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access the worker node which has kubean's deployment, he/she can abuse these excess... Read more
Affected Products :- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
6.7
MEDIUMCVE-2024-5963
Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.... Read more
Affected Products : device_manager- Published: Aug. 06, 2024
- Modified: Aug. 06, 2024
-
7.1
HIGHCVE-2024-22169
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user perm... Read more
Affected Products : wd_discovery- Published: Aug. 02, 2024
- Modified: Aug. 05, 2024
-
9.8
CRITICALCVE-2024-7257
The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for un... Read more
Affected Products :- Published: Aug. 03, 2024
- Modified: Aug. 05, 2024
-
7.2
HIGHCVE-2024-7291
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-le... Read more
Affected Products :- Published: Aug. 03, 2024
- Modified: Aug. 05, 2024
-
7.5
HIGHCVE-2024-28297
SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products :- Published: Aug. 02, 2024
- Modified: Aug. 05, 2024
-
7.5
HIGHCVE-2024-41265
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
4.8
MEDIUMCVE-2024-25948
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
4.8
MEDIUMCVE-2024-25947
Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
4.4
MEDIUMCVE-2024-38489
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
5.8
MEDIUMCVE-2024-38490
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
4.8
MEDIUMCVE-2024-38481
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-39665
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter & Grids allows Stored XSS.This issue affects Filter & Grids: from n/a through 2.9.2.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
5.3
MEDIUMCVE-2024-6567
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to tru... Read more
Affected Products : ebook_store- Published: Aug. 02, 2024
- Modified: Aug. 02, 2024
-
8.8
HIGHCVE-2024-3238
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() func... Read more
Affected Products :- Published: Aug. 02, 2024
- Modified: Aug. 02, 2024