Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-06 CVE-2024-52043 Information Exposure Through an Error Message vulnerability in Humhub
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co.
network
low complexity
humhub CWE-209
5.3
2024-11-06 CVE-2024-9681 Incorrect Comparison vulnerability in Haxx Curl
When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's HSTS cache. The result of a triggered bug is that HTTP accesses to `example.com` get converted to HTTPS for a different period of time than what was asked for by the origin server.
network
high complexity
haxx CWE-697
6.5
2024-11-06 CVE-2024-10020 Unspecified vulnerability in Heateor Social Login
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35.
network
high complexity
heateor
8.1
2024-11-06 CVE-2024-10535 Missing Authorization vulnerability in Martinvalchev Video Gallery for Woocommerce
The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31.
network
low complexity
martinvalchev CWE-862
5.3
2024-11-06 CVE-2024-10543 Missing Authorization vulnerability in Tumult Hype Animations
The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in all versions up to, and including, 1.9.14.
network
low complexity
tumult CWE-862
4.3
2024-11-06 CVE-2024-6626 Missing Authorization vulnerability in Theinnovs Eleforms
The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including, 2.9.9.9.
network
low complexity
theinnovs CWE-862
5.3
2024-11-06 CVE-2024-9307 Unrestricted Upload of File with Dangerous Type vulnerability in Themelooks Mfolio
The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1.
network
low complexity
themelooks CWE-434
8.8
2024-11-06 CVE-2024-9946 Unspecified vulnerability in Heateor Super Socializer
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68.
network
high complexity
heateor
8.1
2024-11-06 CVE-2024-34673 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
local
low complexity
samsung
5.5
2024-11-06 CVE-2024-34674 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
low complexity
samsung
4.6