Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-10467 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3.
network
low complexity
mozilla CWE-787
8.8
2024-10-29 CVE-2024-10468 Race Condition vulnerability in Mozilla Firefox
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash.
network
high complexity
mozilla CWE-362
5.3
2024-10-29 CVE-2024-10474 Unspecified vulnerability in Mozilla Firefox Focus 122.0
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
network
low complexity
mozilla
6.5
2024-10-29 CVE-2024-41153 Command Injection vulnerability in Hitachienergy Tro610 Firmware, Tro620 Firmware and Tro670 Firmware
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands.
network
low complexity
hitachienergy CWE-77
7.2
2024-10-29 CVE-2024-41156 Improper Cross-boundary Removal of Sensitive Data vulnerability in Hitachienergy Tro610 Firmware, Tro620 Firmware and Tro670 Firmware
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats.
network
low complexity
hitachienergy CWE-212
2.7
2024-10-29 CVE-2024-49635 Cross-site Scripting vulnerability in Manzurulhaque Banner Slider
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manzurul Haque Banner Slider allows Reflected XSS.This issue affects Banner Slider: from n/a through 2.1.
network
low complexity
manzurulhaque CWE-79
6.1
2024-10-29 CVE-2024-49636 Cross-site Scripting vulnerability in Prashantmavinkurve Agile Video Player Lite
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Prashant Mavinkurve Agile Video Player Lite allows Reflected XSS.This issue affects Agile Video Player Lite: from n/a through 1.0.
network
low complexity
prashantmavinkurve CWE-79
6.1
2024-10-29 CVE-2024-49637 Cross-site Scripting vulnerability in Foxskav BET WC 2018 Russia
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: from n/a through 2.1.
network
low complexity
foxskav CWE-79
6.1
2024-10-29 CVE-2024-49638 Cross-site Scripting vulnerability in Aliazlan Risk Warning BAR
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali Azlan Risk Warning Bar allows Reflected XSS.This issue affects Risk Warning Bar: from n/a through 1.0.
network
low complexity
aliazlan CWE-79
6.1
2024-10-29 CVE-2024-49639 Cross-site Scripting vulnerability in Edwardstoever Monitor.Chat
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Edward Stoever Monitor.Chat allows Reflected XSS.This issue affects Monitor.Chat: from n/a through 1.1.1.
network
low complexity
edwardstoever CWE-79
6.1