6.4
CVE-2024-4486 - Awesome Contact Form7 for Elementor <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scriptiβ¦
The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP Contact Form 7' widget in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for β¦
0.0
CVE-2024-3708 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
8.3
CVE-2024-5274 - chromium-browser: another type Confusion in V8
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
5.5
CVE-2024-36011 - Bluetooth: HCI: Fix potential null-ptr-deref
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix potential null-ptr-deref in hci_le_big_sync_established_evt().
7.8
CVE-2024-36012 - Bluetooth: msft: fix slab-use-after-free in msft_do_close()
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it in hci_release_dev() to fix the following case: [use] msft_do_close() msft = hdev->msft_data; if (!msft) β¦
6.8
CVE-2024-36013 - Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type void. Nothing is using the returned value but it is ugly to retuβ¦
7.8
CVE-2024-29853 -
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
7.2
CVE-2024-29851 -
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
2.7
CVE-2024-29852 -
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
8.8
CVE-2024-29850 -
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.