Latest Vulnerabilities

In the past week, several significant vulnerabilities have emerged across various software and mobile applications. Notable issues include SQL injection and cross-site scripting vulnerabilities in popular plugins, raising concerns about unauthorized data access and manipulation. Additionally, multiple memory corruption vulnerabilities were discovered in firmware code, potentially impacting device stability and security. Misconfigurations in permission settings have also been highlighted, illustrating risks in user data handling. These vulnerabilities underscore the importance of regular updates and vigilance in maintaining secure systems as attackers continually seek to exploit weaknesses in widely used software.

CVE-2024-8669Backuply – Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection

critical
9.1
First published (updated )

CVE-2024-8039Improper permission configurationDomain configuration vulnerability of the mobile application (com.a…

First published (updated )

CVE-2024-8724Waitlist Woocommerce ( Back in stock notifier ) <= 2.7.5 - Reflected Cross-Site Scripting

medium
6.1
First published (updated )

CVE-2024-8479Simple Spoiler 1.2 - 1.3 - Unauthenticated Arbitrary Shortcode Execution

high
7.3
First published (updated )

CVE-2024-8246Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation

high
8.8
First published (updated )

CVE-2024-8271FOX – Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution

high
7.3
First published (updated )

CVE-2022-3459WooCommerce Multiple Free Gift <= 1.2.3 - Insufficient Server-Side Validation to Arbitrary Gift Adding

medium
5.3
First published (updated )

CVE-2024-44092In TBD of TBD, there is a possible LCS signing enforcement missing due to test/debugging code left …

First published (updated )

CVE-2024-44093In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic err…

First published (updated )

CVE-2024-44094Input Validation

First published (updated )

CVE-2024-44095In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error …

First published (updated )

CVE-2024-44096there is a possible arbitrary read due to an insecure default value. This could lead to local inform…

First published (updated )

CVE-2024-29779there is a possible escalation of privilege due to an unusual root cause. This could lead to local e…

First published (updated )

CVE-2024-6259BT: HCI: adv_ext_report Improper discarding in adv_ext_report

high
7.6
First published (updated )

CVE-2024-6137BT: Classic: SDP OOB access in get_att_search_list

high
7.6
First published (updated )

CVE-2024-6135BT:Classic: Multiple missing buf length checks

high
7.6
First published (updated )

CVE-2024-5931BT: Unchecked user input in bap_broadcast_assistant

medium
6.3
First published (updated )

CVE-2024-6258BT: Missing length checks of net_buf in rfcomm_handle_data

medium
6.8
First published (updated )

CVE-2024-5754BT: Encryption procedure host vulnerability

high
8.2
First published (updated )

npm/lunaryAn improper access control vulnerability exists in lunary-ai/lunary prior to commit 844e8855c7a713dc…

medium
6.5
First published (updated )

npm/lunaryCSRF

high
7.4
First published (updated )

npm/lunaryA broken access control vulnerability exists prior to commit 1f043d8798ad87346dfe378eea723bff78ad743…

medium
6.5
First published (updated )

npm/lunaryAn information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{r…

medium
4.3
First published (updated )

pip/litellmSSRF

high
7.5
First published (updated )

CVE-2024-8784QDocs Smart School Management System Chat mynewuser sql injection

medium
6.5
First published (updated )

CVE-2024-8783OpenTibiaBR MyAAC Post Reply new_post.php cross site scripting

medium
5.3
First published (updated )

CVE-2024-8782JFinalCMS edit delete path traversal

medium
6.5
First published (updated )

CVE-2024-45105An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerabil…

medium
6.7
First published (updated )

CVE-2024-45104A valid, authenticated LXCA user without sufficient privileges may be able to use the device identif…

medium
6.3
First published (updated )

CVE-2024-45103A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA …

medium
4.3
First published (updated )

CVE-2024-45101A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could …

medium
6.8
First published (updated )

CVE-2024-8281OS Command Injection, Input Validation, Command Injection

high
7.2
First published (updated )

CVE-2024-8280OS Command Injection, Input Validation, Command Injection

high
7.2
First published (updated )

CVE-2024-8279OS Command Injection, Command Injection

high
7.2
First published (updated )

CVE-2024-8278OS Command Injection, Command Injection

high
7.2
First published (updated )

CVE-2024-8059IPMI credentials may be captured in XCC audit log entries when the account username length is 16 cha…

medium
4.3
First published (updated )

CVE-2024-7756A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a…

medium
6.8
First published (updated )

CVE-2024-4550Buffer Overflow

medium
6.7
First published (updated )

CVE-2024-3100Buffer Overflow

medium
6.7
First published (updated )

CVE-2024-31416Integer Overflow

medium
5.6
First published (updated )

CVE-2024-31415The Eaton Foreseer software provides the feasibility for the user to configure external servers for …

medium
6.3
First published (updated )

CVE-2024-31414XSS

medium
6.7
First published (updated )

CVE-2024-45368AutomationDirect DirectLogic H2-DM1E Session Fixation

high
8.8
First published (updated )

CVE-2024-43099AutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replay

high
8.8
First published (updated )

F5 Traffix SDCCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

high
7
First published (updated )

npm/lunaryCross-Site Request Forgery (CSRF) in lunary-ai/lunary

high
7.4
First published (updated )

npm/lunaryInformation Disclosure in lunary-ai/lunary

medium
4.3
First published (updated )

npm/lunaryImproper Access Control in lunary-ai/lunary

medium
6.5
First published (updated )

npm/lunaryBroken Access Control in lunary-ai/lunary

medium
6.5
First published (updated )

pip/litellmSSRF in berriai/litellm

high
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203