CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-38826

    Last Modified: 15 Apr 2026

    Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller. The Cloud Foundry project recommends upgrading the following releases: * Upgrade capi release version to 1.194.0 or greater * Upgrade cf-deployment version to v44.1.0 or greater. This includes a patched capi release

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-11068

    Last Modified: 24 Nov 2024

    The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

    Published: 11 Nov 2024
    7.5
    High

    CVE-2024-11067

    Last Modified: 24 Nov 2024

    The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the MAC address through this vulnerability and attempt to log in to the device using the default password.

    Published: 11 Nov 2024
    7.2
    High

    CVE-2024-11066

    Last Modified: 24 Nov 2024

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.

    Published: 11 Nov 2024
    7.2
    High

    CVE-2024-11065

    Last Modified: 15 Nov 2024

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

    Published: 11 Nov 2024
    7.2
    High

    CVE-2024-11064

    Last Modified: 15 Nov 2024

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

    Published: 11 Nov 2024
    7.2
    High

    CVE-2024-11063

    Last Modified: 15 Nov 2024

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

    Published: 11 Nov 2024
    7.2
    High

    CVE-2024-11062

    Last Modified: 15 Nov 2024

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

    Published: 11 Nov 2024
    5.4
    Medium

    CVE-2024-11021

    Last Modified: 18 Nov 2024

    Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-11020

    Last Modified: 18 Nov 2024

    Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 11 Nov 2024
    6.1
    Medium

    CVE-2024-11019

    Last Modified: 18 Nov 2024

    Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-11018

    Last Modified: 18 Nov 2024

    Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.

    Published: 11 Nov 2024
    8.8
    High

    CVE-2024-11017

    Last Modified: 18 Nov 2024

    Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-11016

    Last Modified: 14 Nov 2024

    Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-11060

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical has been found in Jinher Network Collaborative Management Platform 金和数字化智能办公平台 1.0. Affected is an unknown function of the file /C6/JHSoft.Web.AcceptAip/AcceptShow.aspx/. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    5.5
    Medium

    CVE-2024-11079

    Last Modified: 29 Jun 2026

    A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks.

    Published: 11 Nov 2024
    6.5
    Medium

    CVE-2024-49393

    Last Modified: 26 Jun 2026

    In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-51135

    Last Modified: 15 Apr 2026

    An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

    Published: 11 Nov 2024
    8.1
    High

    CVE-2024-48322

    Last Modified: 15 Apr 2026

    UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

    Published: 11 Nov 2024
    7.5
    High

    CVE-2024-25253

    Last Modified: 15 Apr 2026

    Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-25255

    Last Modified: 15 Apr 2026

    Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-49395

    Last Modified: 26 Jun 2026

    In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.

    Published: 11 Nov 2024
    5.9
    Medium

    CVE-2025-2312

    Last Modified: 15 Apr 2026

    A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

    Published: 11 Nov 2024
    6.5
    Medium

    CVE-2024-52531

    Last Modified: 3 Nov 2025

    GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-52533

    Last Modified: 17 Jun 2025

    gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

    Published: 11 Nov 2024
    6.1
    Medium

    CVE-2024-51213

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-51190

    Last Modified: 1 Apr 2025

    TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-51189

    Last Modified: 1 Apr 2025

    TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-51187

    Last Modified: 1 Apr 2025

    TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.

    Published: 11 Nov 2024
    8
    High

    CVE-2024-51186

    Last Modified: 7 May 2025

    D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

    Published: 11 Nov 2024
    7.8
    High

    CVE-2024-50263

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error There is no reason to invoke these hooks early against an mm that is in an incomplete state. The change in commit d24062914837 ("fork: use __mt_dup() to duplicate maple tree in dup_mmap()") makes this more pertinent as we may be in a state where entries in the maple tree are not yet consistent. Their placement early in dup_mmap() only appears to have been meaningful for early error checking, and since functionally it'd require a very small allocation to fail (in practice 'too small to fail') that'd only occur in the most dire circumstances, meaning the fork would fail or be OOM'd in any case. Since both khugepaged and KSM tracking are there to provide optimisations to memory performance rather than critical functionality, it doesn't really matter all that much if, under such dire memory pressure, we fail to register an mm with these. As a result, we follow the example of commit d2081b2bf819 ("mm: khugepaged: make khugepaged_enter() void function") and make ksm_fork() a void function also. We only expose the mm to these functions once we are done with them and only if no error occurred in the fork operation.

    Published: 11 Nov 2024
    6.1
    Medium

    CVE-2024-50601

    Last Modified: 15 Apr 2026

    Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-51054

    Last Modified: 27 Mar 2025

    A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST request parameter.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-51188

    Last Modified: 1 Apr 2025

    TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.

    Published: 11 Nov 2024
    5.4
    Medium

    CVE-2024-46965

    Last Modified: 15 Apr 2026

    The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.

    Published: 11 Nov 2024
    7.5
    High

    CVE-2024-48939

    Last Modified: 15 Apr 2026

    Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-36061

    Last Modified: 26 Jan 2026

    EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-25254

    Last Modified: 24 Jun 2025

    SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-50636

    Last Modified: 15 Apr 2026

    PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote Command Execution (RCE). This vulnerability arises because PyMOL treats .PYM files as Python scripts without properly validating or restricting the commands within the script, enabling attackers to run unauthorized commands in the context of the user running the application.

    Published: 11 Nov 2024
    7.5
    High

    CVE-2024-52530

    Last Modified: 3 Nov 2025

    GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

    Published: 11 Nov 2024
    7.5
    High

    CVE-2024-52532

    Last Modified: 3 Nov 2025

    GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-44546

    Last Modified: 27 Jun 2025

    Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

    Published: 11 Nov 2024
    8.8
    High

    CVE-2024-41992

    Last Modified: 15 Apr 2026

    Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

    Published: 11 Nov 2024
    9.1
    Critical

    CVE-2024-46962

    Last Modified: 15 Apr 2026

    The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.

    Published: 11 Nov 2024
    8.1
    High

    CVE-2024-46963

    Last Modified: 15 Apr 2026

    The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.

    Published: 11 Nov 2024
    8.1
    High

    CVE-2024-46964

    Last Modified: 15 Apr 2026

    The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.

    Published: 11 Nov 2024
    8.1
    High

    CVE-2024-46966

    Last Modified: 15 Apr 2026

    The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-49394

    Last Modified: 26 Jun 2026

    In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-50667

    Last Modified: 1 Apr 2025

    The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.

    Published: 11 Nov 2024
    9.8
    Critical

    CVE-2024-50989

    Last Modified: 27 Mar 2025

    A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.

    Published: 11 Nov 2024