Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-30915 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component. | |||||
| CVE-2024-30890 | 2024-07-03 | N/A | N/A | ||
| Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component. | |||||
| CVE-2024-30862 | 2024-07-03 | N/A | 8.8 HIGH | ||
| netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php. | |||||
| CVE-2024-30800 | 2024-07-03 | N/A | 6.3 MEDIUM | ||
| PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function. | |||||
| CVE-2024-30799 | 2024-07-03 | N/A | 4.4 MEDIUM | ||
| An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function. | |||||
| CVE-2024-30637 | 2024-07-03 | N/A | 8.8 HIGH | ||
| Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter. | |||||
| CVE-2024-30623 | 2024-07-03 | N/A | 6.5 MEDIUM | ||
| Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function. | |||||
| CVE-2024-30419 | 2024-07-03 | N/A | 5.4 MEDIUM | ||
| Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product. | |||||
| CVE-2024-30165 | 2024-07-03 | N/A | 7.1 HIGH | ||
| Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164. | |||||
| CVE-2024-30164 | 2024-07-03 | N/A | 6.7 MEDIUM | ||
| Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resolution is the same as for CVE-2024-30165, this vulnerability on macOS is not the same as CVE-2024-30165. | |||||
| CVE-2024-30162 | 2024-07-03 | N/A | 7.2 HIGH | ||
| Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user. | |||||
| CVE-2024-30119 | 2024-07-03 | N/A | 3.7 LOW | ||
| HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection. | |||||
| CVE-2024-30107 | 2024-07-03 | N/A | 3.5 LOW | ||
| HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios. | |||||
| CVE-2024-30058 | 2024-07-03 | N/A | 5.4 MEDIUM | ||
| Microsoft Edge (Chromium-based) Spoofing Vulnerability | |||||
| CVE-2024-2975 | 2024-07-03 | N/A | 8.8 HIGH | ||
| A race condition was identified through which privilege escalation was possible in certain configurations. | |||||
| CVE-2024-2908 | 2024-07-03 | N/A | 4.3 MEDIUM | ||
| The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
| CVE-2024-2887 | 2024-07-03 | N/A | 8.1 HIGH | ||
| Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2024-2886 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2024-2885 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2024-2883 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |||||
