941
|
9.0 |
CRITICAL
Network
|
apache intel cvat siemens debian sonicwall fedoraproject
|
log4j oneapi audio_development_kit datacenter_manager system_debugger secure_device_onboard sensor_solution_firmware_development_kit genomics_kernel_library system_studio c…
|
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC)…
Update
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2021-45046
|
2024-10-31 21:17 |
2021-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
942
|
6.1 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Store…
Update
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2023-6529
|
2024-10-31 20:45 |
2024-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
943
|
4.3 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitr…
Update
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2023-1414
|
2024-10-31 20:45 |
2023-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
944
|
6.1 |
MEDIUM
Network
|
rextheme
|
wp_vr
|
The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against h…
Update
|
-
|
CVE-2023-1413
|
2024-10-31 20:45 |
2023-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
945
|
8.8 |
HIGH
Network
|
rextheme
|
wp_vr
|
Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.
Update
|
CWE-352
Origin Validation Error
|
CVE-2023-25708
|
2024-10-31 20:45 |
2023-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
946
|
- |
|
-
|
-
|
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "U…
Update
|
-
|
CVE-2024-8376
|
2024-10-31 19:15 |
2024-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
947
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Update
|
CWE-843
Type Confusion
|
CVE-2024-10230
|
2024-10-31 17:35 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
948
|
6.1 |
MEDIUM
Network
|
hms-networks
|
ewon_cosy\+_firmware
|
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-33893
|
2024-10-31 17:35 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
949
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Fix possible use-after-free issue in ftrace_location()
KASAN reports a bug:
BUG: KASAN: use-after-free in ftrace_locat…
Update
|
CWE-416
Use After Free
|
CVE-2024-38588
|
2024-10-31 17:35 |
2024-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
950
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of ser…
Update
|
CWE-22
Path Traversal
|
CVE-2024-9676
|
2024-10-31 14:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|