| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26529 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2024 | An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c. | ||
| CVE-2024-2400 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2024 | Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-7072 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data… | ||
| CVE-2024-2395 | Hig | 0.47 | 7.3 | 0.00 | Mar 12, 2024 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to… | ||
| CVE-2024-0386 | Hig | 0.47 | 7.2 | 0.01 | Mar 12, 2024 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | ||
| CVE-2024-28236 | Hig | 0.43 | 7.7 | 0.01 | Mar 12, 2024 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields like `parameters`, `image` and `entrypoint` to inject secrets into a plugin/image and — by using… | ||
| CVE-2024-24092 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php. | ||
| CVE-2024-23300 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. | ||
| CVE-2024-28186 | Hig | 0.00 | 7.1 | 0.01 | Mar 12, 2024 | FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the application. This issue arises from the… | ||
| CVE-2024-28121 | Hig | 0.50 | 8.8 | 0.02 | Mar 12, 2024 | stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. In affected versions more methods than expected can be called on reflex instances. Being able to call some of… | ||
| CVE-2024-28114 | Hig | 0.00 | 8.1 | 0.01 | Mar 12, 2024 | Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This… | ||
| CVE-2023-5410 | Hig | 0.53 | 8.2 | 0.00 | Mar 12, 2024 | A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation for the potential vulnerability. | ||
| CVE-2024-27894 | Hig | 0.55 | 8.5 | 0.02 | Mar 12, 2024 | The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the… | ||
| CVE-2024-27317 | Hig | 0.59 | 8.4 | 0.57 | Mar 12, 2024 | In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. This occurs when… | ||
| CVE-2024-27135 | Hig | 0.56 | 8.5 | 0.06 | Mar 12, 2024 | Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar… | ||
| CVE-2022-34321 | Hig | 0.53 | 8.2 | 0.02 | Mar 12, 2024 | Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of… | ||
| CVE-2024-1138 | Hig | 0.57 | 8.8 | 0.00 | Mar 12, 2024 | The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL… | ||
| CVE-2024-28340 | Hig | 0.49 | 7.5 | 0.01 | Mar 12, 2024 | An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required. | ||
| CVE-2024-28338 | Hig | 0.52 | 8.0 | 0.01 | Mar 12, 2024 | A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie. | ||
| CVE-2024-26204 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Outlook for Android Information Disclosure Vulnerability | ||
| CVE-2024-26203 | Hig | 0.48 | 7.3 | 0.01 | Mar 12, 2024 | Azure Data Studio Elevation of Privilege Vulnerability | ||
| CVE-2024-26199 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2024-26198 | Hig | 0.58 | 8.8 | 0.07 | Mar 12, 2024 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2024-26190 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2024-26182 | Hig | 0.51 | 7.8 | 0.06 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-26178 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-26176 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-26173 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-26170 | Hig | 0.51 | 7.8 | 0.07 | Mar 12, 2024 | Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | ||
| CVE-2024-26169 | Hig | 0.69 | 7.8 | 0.04 | KEV | Mar 12, 2024 | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| CVE-2024-26166 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-26165 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Visual Studio Code Elevation of Privilege Vulnerability | ||
| CVE-2024-26164 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-26162 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-26161 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-26159 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21451 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21450 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-21446 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2024-21445 | Hig | 0.46 | 7.0 | 0.01 | Mar 12, 2024 | Windows USB Print Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-21444 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-21443 | Hig | 0.48 | 7.3 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-21442 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows USB Print Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-21441 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-21440 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21439 | Hig | 0.46 | 7.0 | 0.01 | Mar 12, 2024 | Windows Telephony Server Elevation of Privilege Vulnerability | ||
| CVE-2024-21438 | Hig | 0.49 | 7.5 | 0.03 | Mar 12, 2024 | Microsoft AllJoyn API Denial of Service Vulnerability | ||
| CVE-2024-21437 | Hig | 0.51 | 7.8 | 0.08 | Mar 12, 2024 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2024-21436 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2024-21435 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Windows OLE Remote Code Execution Vulnerability |
- risk 0.49cvss 7.5epss 0.01
An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.
- risk 0.57cvss 8.8epss 0.01
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.49cvss 7.5epss 0.01
The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data…
- risk 0.47cvss 7.3epss 0.00
The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to…
- risk 0.47cvss 7.2epss 0.01
The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
- risk 0.43cvss 7.7epss 0.01
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields like `parameters`, `image` and `entrypoint` to inject secrets into a plugin/image and — by using…
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
- risk 0.51cvss 7.8epss 0.00
A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
- risk 0.00cvss 7.1epss 0.01
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the application. This issue arises from the…
- risk 0.50cvss 8.8epss 0.02
stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. In affected versions more methods than expected can be called on reflex instances. Being able to call some of…
- risk 0.00cvss 8.1epss 0.01
Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This…
- risk 0.53cvss 8.2epss 0.00
A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation for the potential vulnerability.
- risk 0.55cvss 8.5epss 0.02
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the…
- risk 0.59cvss 8.4epss 0.57
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. This occurs when…
- risk 0.56cvss 8.5epss 0.06
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar…
- risk 0.53cvss 8.2epss 0.02
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of…
- risk 0.57cvss 8.8epss 0.00
The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL…
- risk 0.49cvss 7.5epss 0.01
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
- risk 0.52cvss 8.0epss 0.01
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
- risk 0.49cvss 7.5epss 0.02
Outlook for Android Information Disclosure Vulnerability
- risk 0.48cvss 7.3epss 0.01
Azure Data Studio Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.07
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft QUIC Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.06
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.04
Windows Error Reporting Service Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Visual Studio Code Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
NTFS Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows USB Print Driver Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows USB Print Driver Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Telephony Server Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft AllJoyn API Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.08
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows OLE Remote Code Execution Vulnerability