Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2024
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
CVSS Score
7.2
EPSS Score
0.008
Published
2024-11-07
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
CVSS Score
7.5
EPSS Score
0.005
Published
2024-11-07
A flaw was found in moodle. A local file may include risks when restoring block backups.
CVSS Score
7.5
EPSS Score
0.006
Published
2024-11-07
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
CVSS Score
8.1
EPSS Score
0.874
Published
2024-11-07
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
CVSS Score
7.5
EPSS Score
0.007
Published
2024-11-07
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
CVSS Score
7.7
EPSS Score
0.002
Published
2024-11-07
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
CVSS Score
7.5
EPSS Score
0.005
Published
2024-11-07
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Score
6.4
EPSS Score
0.003
Published
2024-11-07
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
CVSS Score
8.0
EPSS Score
0.004
Published
2024-11-07
In the Linux kernel, the following vulnerability has been resolved: vsock: Update rx_bytes on read_skb() Make sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt() calls are balanced (i.e. virtio_vsock_sock::rx_bytes doesn't lie) after vsock_transport::read_skb(). While here, also inform the peer that we've freed up space and it has more credit. Failing to update rx_bytes after packet is dequeued leads to a warning on SOCK_STREAM recv(): [ 233.396654] rx_queue is empty, but rx_bytes is non-zero [ 233.396702] WARNING: CPU: 11 PID: 40601 at net/vmw_vsock/virtio_transport_common.c:589
CVSS Score
5.5
EPSS Score
0.002
Published
2024-11-07


Contact Us

Shodan ® - All rights reserved