CVE Notify
19.4K subscribers
4 photos
223K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-37389
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authenticated user. Upgrading to Apache NiFi 1.27.0 or 2.0.0-M4 is the recommended mitigation.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-26531
Cross-Site Request Forgery (CSRF) vulnerability in ้—ช็”ตๅš ๅคšๅˆไธ€ๆœ็ดข่‡ชๅŠจๆŽจ้€็ฎก็†ๆ’ไปถ-ๆ”ฏๆŒBaidu/Google/Bing/IndexNow/Yandex/ๅคดๆก allows Cross Site Request Forgery.This issue affects ๅคšๅˆไธ€ๆœ็ดข่‡ชๅŠจๆŽจ้€็ฎก็†ๆ’ไปถ-ๆ”ฏๆŒBaidu/Google/Bing/IndexNow/Yandex/ๅคดๆก: from n/a through 4.2.7.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-49188
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-47420
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-45830
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35778
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This issue affects Slideshow SE: from n/a through 2.5.17.

๐ŸŽ–@cveNotify
๐Ÿ‘1
๐Ÿšจ CVE-2023-28696
Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-24974
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-27459
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-27903
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-37999
A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.

๐ŸŽ–@cveNotify
๐Ÿ‘1
๐Ÿšจ CVE-2019-8761
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. Parsing a maliciously crafted text file may lead to disclosure of user information.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2017-16231
In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be used to limit the amount of stack that is used

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2022-2856
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-28334
Authenticated users were able to enumerate other users' names via the learning plans page.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-21237
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-47246
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30595
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.

๐ŸŽ–@cveNotify