CVE Notify
19.4K subscribers
4 photos
223K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-5711
Cross-site Scripting (XSS) - Stored in GitHub repository stitionai/devika prior to -.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-39723
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-31897
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-37528
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 294293.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-5090
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-4418
A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-34602
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-34603
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-37389
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-26531
Cross-Site Request Forgery (CSRF) vulnerability in ้—ช็”ตๅš ๅคšๅˆไธ€ๆœ็ดข่‡ชๅŠจๆŽจ้€็ฎก็†ๆ’ไปถ-ๆ”ฏๆŒBaidu/Google/Bing/IndexNow/Yandex/ๅคดๆก allows Cross Site Request Forgery.This issue affects ๅคšๅˆไธ€ๆœ็ดข่‡ชๅŠจๆŽจ้€็ฎก็†ๆ’ไปถ-ๆ”ฏๆŒBaidu/Google/Bing/IndexNow/Yandex/ๅคดๆก: from n/a through 4.2.7.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-49188
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-47420
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-45830
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35778
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This issue affects Slideshow SE: from n/a through 2.5.17.

๐ŸŽ–@cveNotify
๐Ÿ‘1
๐Ÿšจ CVE-2023-28696
Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-24974
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-27459
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-27903
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

๐ŸŽ–@cveNotify