NA - CVE-2024-43793 - Halo is an open source website building tool. A...
Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute...
NA - CVE-2024-4465 - An access control vulnerability was discovered...
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with...
NA - CVE-2024-8306 - CWE-269: Improper Privilege Management...
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated...
High - CVE-2024-39378 - Audition versions 24.4.1, 23.6.6 and earlier...
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of...
Medium - CVE-2024-41868 - Audition versions 24.4.1, 23.6.6 and earlier...
Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to...
NA - CVE-2024-44466 - COMFAST CF-XR11 V2.7.2 has a command injection...
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.
NA - CVE-2024-44851 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the...
NA - CVE-2024-45009 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ......
NA - CVE-2024-45010 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available Adding the following warning ......
NA - CVE-2024-45011 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing device Ensure, as the driver probes the device, that all endpoints that the...