A vulnerability, which was classified as problematic, was found in Apple macOS up to 13.6/14.6. This affects an unknown part of the component File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-44237. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Tiki up to 27.0. Affected is an unknown function of the file tiki-admin_modules.php of the component Module Handler. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is traded as CVE-2024-51509. It is possible to launch the attack remotely. There is no exploit available.
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
vxlan: Fix uninit-value in vxlan_vnifilter_dump()
KMSAN reported an uninit-value access in vxlan_vnifilter_dump() [1].
If the length of the netlink message payload is less than
sizeof(struct tunnel_msg), ...
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
net: davicom: fix UAF in dm9000_drv_remove
dm is netdev private data and it cannot be
used after free_netdev() call. Using dm after free_netdev()
can cause UAF bug. Fix it by moving free_netdev() at the end of ...
A vulnerability has been found in Tiki up to 27.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Create a Wiki Pages. The manipulation of the argument description leads to cross site scripting.
This vulnerability is known as CVE-2024-51506. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Tiki up to 27.0 and classified as problematic. Affected by this issue is some unknown functionality of the component External Wiki. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is handled as CVE-2024-51507. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Tiki up to 27.0. It has been classified as problematic. This affects an unknown part of the component External Wiki. The manipulation of the argument Index leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-51508. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in SMSAlert Plugin up to 3.7.5 on WordPress and classified as problematic. This vulnerability affects the function sa_subscribe of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-10233. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Beaver Builder Plugin up to 2.8.4.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Button Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-9505. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Arconix Shortcodes Plugin up to 2.1.13 on WordPress. It has been classified as problematic. Affected is the function box of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10226. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Newsletters Plugin up to 4.9.9.4 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function newsletters_video of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-10181. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.10. Affected is the function cond_resched. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-21694. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.