| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45139 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-45138 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-45720 | Hig | 0.46 | 8.2 | 0.01 | Oct 9, 2024 | On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially… | ||
| CVE-2024-28168 | Hig | 0.42 | 7.5 | 0.01 | Oct 9, 2024 | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue. | ||
| CVE-2024-47334 | Hig | 0.49 | 7.6 | 0.00 | Oct 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1. | ||
| CVE-2024-9575 | Hig | 0.55 | — | 0.01 | Oct 9, 2024 | Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5. | ||
| CVE-2024-47418 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47417 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-47416 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-47415 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47414 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47413 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47412 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47411 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-47410 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-45150 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-45146 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2023-37154 | Hig | 0.48 | 8.4 | 0.00 | Oct 9, 2024 | check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior. | ||
| CVE-2024-47191 | Hig | 0.39 | 7.1 | 0.00 | Oct 9, 2024 | pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. | ||
| CVE-2024-45179 | Hig | 0.47 | 7.2 | 0.03 | Oct 9, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection… | ||
| CVE-2024-35288 | Hig | 0.51 | 7.8 | 0.00 | Oct 9, 2024 | Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT… | ||
| CVE-2024-9603 | Hig | 0.57 | 8.8 | 0.00 | Oct 8, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2024-9602 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2024-9412 | — | Hig | 0.55 | — | 0.00 | Oct 8, 2024 | An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If… | |
| CVE-2024-47773 | Hig | 0.56 | 8.2 | 0.02 | Oct 8, 2024 | Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest… | ||
| CVE-2024-46539 | Hig | 0.53 | 8.2 | 0.00 | Oct 8, 2024 | Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS). | ||
| CVE-2024-43616 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2024-43615 | Hig | 0.46 | 7.1 | 0.01 | Oct 8, 2024 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | ||
| CVE-2024-43611 | Hig | 0.57 | 8.8 | 0.02 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43608 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43607 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43601 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Visual Studio Code for Linux Remote Code Execution Vulnerability | ||
| CVE-2024-43599 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2024-43593 | Hig | 0.57 | 8.8 | 0.02 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43592 | Hig | 0.57 | 8.8 | 0.02 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43591 | Hig | 0.57 | 8.7 | 0.02 | Oct 8, 2024 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | ||
| CVE-2024-43590 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | Visual C++ Redistributable Installer Elevation of Privilege Vulnerability | ||
| CVE-2024-43589 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43584 | Hig | 0.50 | 7.7 | 0.01 | Oct 8, 2024 | Windows Scripting Engine Security Feature Bypass Vulnerability | ||
| CVE-2024-43583 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Winlogon Elevation of Privilege Vulnerability | ||
| CVE-2024-43582 | Hig | 0.53 | 8.1 | 0.03 | Oct 8, 2024 | Remote Desktop Protocol Server Remote Code Execution Vulnerability | ||
| CVE-2024-43581 | Hig | 0.46 | 7.1 | 0.01 | Oct 8, 2024 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | ||
| CVE-2024-43576 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2024-43575 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-43574 | Hig | 0.54 | 8.3 | 0.01 | Oct 8, 2024 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | ||
| CVE-2024-43572 | Hig | 0.68 | 7.8 | 0.67 | KEV | Oct 8, 2024 | Microsoft Management Console Remote Code Execution Vulnerability | |
| CVE-2024-43567 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2024-43565 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2024 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | ||
| CVE-2024-43564 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-43563 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2024 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.46cvss 8.2epss 0.01
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially…
- risk 0.42cvss 7.5epss 0.01
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.
- risk 0.49cvss 7.6epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1.
- risk 0.55cvss —epss 0.01
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.48cvss 8.4epss 0.00
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
- risk 0.39cvss 7.1epss 0.00
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.
- risk 0.47cvss 7.2epss 0.03
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection…
- risk 0.51cvss 7.8epss 0.00
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT…
- risk 0.57cvss 8.8epss 0.00
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- risk 0.55cvss —epss 0.00
An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If…
- risk 0.56cvss 8.2epss 0.02
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest…
- risk 0.53cvss 8.2epss 0.00
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Code for Linux Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.7epss 0.02
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.50cvss 7.7epss 0.01
Windows Scripting Engine Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Winlogon Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.03
Remote Desktop Protocol Server Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft Office Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Hyper-V Denial of Service Vulnerability
- risk 0.54cvss 8.3epss 0.01
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
- risk 0.68cvss 7.8epss 0.67
Microsoft Management Console Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Hyper-V Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Network Address Translation (NAT) Denial of Service Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability