Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-09 CVE-2024-39586 XXE vulnerability in Dell EMC Appsync
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability.
low complexity
dell CWE-611
4.3
2024-10-09 CVE-2024-9449 The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2024-10-09 CVE-2024-32608 Out-of-bounds Write vulnerability in Hdfgroup Hdf5
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
network
low complexity
hdfgroup CWE-787
critical
9.8
2024-10-09 CVE-2024-7963 The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-10-08 CVE-2024-9602 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2024-10-08 CVE-2024-9603 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2024-10-08 CVE-2024-30092 Unspecified vulnerability in Microsoft products
Windows Hyper-V Remote Code Execution Vulnerability
high complexity
microsoft
7.5
2024-10-08 CVE-2024-37976 Unspecified vulnerability in Microsoft products
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
local
low complexity
microsoft
6.7
2024-10-08 CVE-2024-37979 Unspecified vulnerability in Microsoft products
Windows Kernel Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-10-08 CVE-2024-37982 Unspecified vulnerability in Microsoft products
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
local
low complexity
microsoft
7.8