Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 31934 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-0002 1 Purestorage 1 Purity\/\/fa 2024-09-27 N/A 9.8 CRITICAL
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
CVE-2024-6482 1 Idehweb 1 Login With Phone Number 2024-09-27 N/A 8.8 HIGH
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40. The login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49.
CVE-2024-7898 1 Tosei-corporation 1 Online Store Management System 2024-09-27 N/A 9.8 CRITICAL
A vulnerability classified as critical was found in Tosei Online Store Management System ??????????? 4.02/4.03/4.04. This vulnerability affects unknown code of the component Backend. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-3775 1 Hashicorp 1 Vault 2024-09-26 N/A 4.9 MEDIUM
A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespace can be applied to requests outside in another non-descendant namespace, potentially resulting in denial of service. Fixed in Vault Enterprise 1.15.0, 1.14.4, 1.13.8.
CVE-2024-6499 1 Maxfoundry 1 Maxbuttons 2024-09-26 N/A 5.3 MEDIUM
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
CVE-2024-8247 1 Tribulant 1 Newsletters 2024-09-26 N/A 8.8 HIGH
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator. Please note that this only affects users with access to edit/update screen options, which means an administrator would need to grant lower privilege users with access to the Sent & Draft Emails page of the plugin in order for this to be exploited.
CVE-2023-32426 1 Apple 1 Macos 2024-09-26 N/A 7.8 HIGH
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.
CVE-2023-29166 1 Apple 1 Pro Video Formats 2024-09-26 N/A 8.8 HIGH
A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.
CVE-2024-38156 1 Microsoft 1 Edge 2024-09-26 N/A 6.1 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-41934 1 Jenkins 1 Pipeline Maven Integration 2024-09-26 N/A 5.3 MEDIUM
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
CVE-2023-2816 1 Hashicorp 1 Consul 2024-09-26 N/A 6.5 MEDIUM
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
CVE-2024-8891 1 Circutor 2 Q-smt, Q-smt Firmware 2024-09-26 N/A 5.3 MEDIUM
An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
CVE-2024-47145 1 Mattermost 1 Mattermost Server 2024-09-26 N/A 4.3 MEDIUM
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
CVE-2024-47003 1 Mattermost 1 Mattermost Server 2024-09-26 N/A 6.5 MEDIUM
Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.
CVE-2023-39321 1 Golang 1 Go 2024-09-26 N/A 7.5 HIGH
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVE-2023-39620 1 Buffalo 2 Terastation Nas 5410r, Terastation Nas 5410r Firmware 2024-09-26 N/A 7.5 HIGH
An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function.
CVE-2023-39584 1 Hexo 1 Hexo 2024-09-26 N/A 7.5 HIGH
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
CVE-2023-41578 1 Jeecg 1 Jeecg Boot 2024-09-26 N/A 7.5 HIGH
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
CVE-2024-7493 1 Wpcom 1 Wpcom Member 2024-09-26 N/A 9.8 CRITICAL
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an administrator during registration.
CVE-2023-4876 1 Hamza417 1 Inure 2024-09-26 N/A 7.5 HIGH
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.