| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-10430 | Hig | 0.48 | 7.3 | 0.01 | Oct 27, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0. This issue affects some unknown processing of the file /animalsupdate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated… | ||
| CVE-2024-50616 | Hig | 0.57 | 8.8 | 0.00 | Oct 27, 2024 | Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information. | ||
| CVE-2024-50611 | Hig | 0.40 | 7.2 | 0.01 | Oct 27, 2024 | CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a… | ||
| CVE-2024-10429 | Hig | 0.48 | 7.2 | 0.18 | Oct 27, 2024 | A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection.… | ||
| CVE-2024-10428 | Hig | 0.48 | 7.2 | 0.15 | Oct 27, 2024 | A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be… | ||
| CVE-2020-26311 | Hig | 0.42 | 7.5 | 0.01 | Oct 26, 2024 | Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available. | ||
| CVE-2020-26310 | Hig | 0.57 | — | 0.00 | Oct 26, 2024 | Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are… | ||
| CVE-2020-26309 | Hig | 0.50 | — | 0.00 | Oct 26, 2024 | Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available. | ||
| CVE-2020-26308 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2024 | Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | ||
| CVE-2020-26307 | Hig | 0.57 | — | 0.00 | Oct 26, 2024 | HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | ||
| CVE-2020-26306 | Hig | 0.50 | — | 0.00 | Oct 26, 2024 | Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no… | ||
| CVE-2020-26305 | Hig | 0.49 | 7.5 | 0.00 | Oct 26, 2024 | CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | ||
| CVE-2020-26304 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2024 | Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available. | ||
| CVE-2020-26303 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2024 | insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | ||
| CVE-2024-10402 | Hig | 0.49 | 7.5 | 0.01 | Oct 26, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers,… | ||
| CVE-2024-9772 | Hig | 0.48 | 7.3 | 0.01 | Oct 26, 2024 | The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before… | ||
| CVE-2024-9637 | Hig | 0.50 | 8.8 | 0.00 | Oct 26, 2024 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like… | ||
| CVE-2024-8392 | Hig | 0.40 | 7.2 | 0.01 | Oct 26, 2024 | The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.6 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and… | ||
| CVE-2024-0128 | Hig | 0.46 | 7.1 | 0.00 | Oct 26, 2024 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges. | ||
| CVE-2024-0127 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might… | ||
| CVE-2024-0126 | Hig | 0.53 | 8.2 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure,… | ||
| CVE-2024-0121 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-0120 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-0119 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-0118 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-0117 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-9890 | Hig | 0.50 | 8.8 | 0.01 | Oct 26, 2024 | The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions… | ||
| CVE-2024-48230 | Hig | 0.47 | 7.2 | 0.00 | Oct 25, 2024 | funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | ||
| CVE-2024-48229 | Hig | 0.47 | 7.2 | 0.00 | Oct 25, 2024 | funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | ||
| CVE-2024-48226 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | ||
| CVE-2024-48223 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | ||
| CVE-2024-48222 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | ||
| CVE-2024-48218 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | ||
| CVE-2024-49767 | Hig | 0.42 | 7.5 | 0.01 | Oct 25, 2024 | Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively… | ||
| CVE-2024-37847 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2024 | An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2024-37845 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. | ||
| CVE-2024-48700 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component. | ||
| CVE-2024-48655 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2024 | An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | ||
| CVE-2024-48459 | Hig | 0.48 | 7.3 | 0.08 | Oct 25, 2024 | A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An attacker can exploit this vulnerability by constructing a malicious payload to… | ||
| CVE-2024-10387 | Hig | 0.49 | 7.5 | 0.08 | Oct 25, 2024 | CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service. | ||
| CVE-2022-30358 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2024 | OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required. | ||
| CVE-2022-30357 | Hig | 0.57 | 8.8 | 0.00 | Oct 25, 2024 | OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required. | ||
| CVE-2022-30354 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2024 | OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers. | ||
| CVE-2024-49757 | Hig | 0.42 | 7.5 | 0.03 | Oct 25, 2024 | The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option… | ||
| CVE-2024-49381 | Hig | 0.42 | 7.5 | 0.01 | Oct 25, 2024 | Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2… | ||
| CVE-2024-49380 | Hig | 0.42 | 7.5 | 0.03 | Oct 25, 2024 | Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version… | ||
| CVE-2024-9991 | Hig | 0.46 | — | 0.00 | Oct 25, 2024 | This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi… | ||
| CVE-2024-49376 | Hig | 0.50 | 8.8 | 0.00 | Oct 25, 2024 | Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by… | ||
| CVE-2024-47041 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2024 | In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-47035 | Hig | 0.51 | 7.8 | 0.00 | Oct 25, 2024 | In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
- risk 0.48cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0. This issue affects some unknown processing of the file /animalsupdate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated…
- risk 0.57cvss 8.8epss 0.00
Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.
- risk 0.40cvss 7.2epss 0.01
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a…
- risk 0.48cvss 7.2epss 0.18
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection.…
- risk 0.48cvss 7.2epss 0.15
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be…
- risk 0.42cvss 7.5epss 0.01
Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.
- risk 0.57cvss —epss 0.00
Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are…
- risk 0.50cvss —epss 0.00
Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available.
- risk 0.49cvss 7.5epss 0.01
Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
- risk 0.57cvss —epss 0.00
HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
- risk 0.50cvss —epss 0.00
Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no…
- risk 0.49cvss 7.5epss 0.00
CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
- risk 0.49cvss 7.5epss 0.01
Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
- risk 0.49cvss 7.5epss 0.01
insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
- risk 0.49cvss 7.5epss 0.01
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers,…
- risk 0.48cvss 7.3epss 0.01
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before…
- risk 0.50cvss 8.8epss 0.00
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like…
- risk 0.40cvss 7.2epss 0.01
The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.6 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and…
- risk 0.46cvss 7.1epss 0.00
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
- risk 0.51cvss 7.8epss 0.00
NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might…
- risk 0.53cvss 8.2epss 0.00
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…
- risk 0.50cvss 8.8epss 0.01
The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions…
- risk 0.47cvss 7.2epss 0.00
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
- risk 0.47cvss 7.2epss 0.00
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
- risk 0.47cvss 7.2epss 0.01
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
- risk 0.42cvss 7.5epss 0.01
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively…
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
- risk 0.47cvss 7.2epss 0.01
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
- risk 0.47cvss 7.2epss 0.01
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
- risk 0.57cvss 8.8epss 0.01
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
- risk 0.48cvss 7.3epss 0.08
A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An attacker can exploit this vulnerability by constructing a malicious payload to…
- risk 0.49cvss 7.5epss 0.08
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.
- risk 0.57cvss 8.8epss 0.01
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.
- risk 0.57cvss 8.8epss 0.00
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.
- risk 0.49cvss 7.5epss 0.01
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.
- risk 0.42cvss 7.5epss 0.03
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option…
- risk 0.42cvss 7.5epss 0.01
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2…
- risk 0.42cvss 7.5epss 0.03
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version…
- risk 0.46cvss —epss 0.00
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi…
- risk 0.50cvss 8.8epss 0.00
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by…
- risk 0.51cvss 7.8epss 0.00
In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…