CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2024-20124

    Last Modified: 22 Apr 2025

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1568.

    Published: 4 Nov 2024
    4.4
    Medium

    CVE-2024-20123

    Last Modified: 22 Apr 2025

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1569.

    Published: 4 Nov 2024
    4.4
    Medium

    CVE-2024-20122

    Last Modified: 22 Apr 2025

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1572.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20121

    Last Modified: 22 Apr 2025

    In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1574.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20120

    Last Modified: 22 Apr 2025

    In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08956986; Issue ID: MSV-1575.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20119

    Last Modified: 22 Apr 2025

    In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062301; Issue ID: MSV-1620.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20118

    Last Modified: 22 Apr 2025

    In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09062392; Issue ID: MSV-1621.

    Published: 4 Nov 2024
    4.4
    Medium

    CVE-2024-20117

    Last Modified: 22 Apr 2025

    In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09008925; Issue ID: MSV-1681.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20115

    Last Modified: 22 Apr 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036695; Issue ID: MSV-1713.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20114

    Last Modified: 13 Mar 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09037038; Issue ID: MSV-1714.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20113

    Last Modified: 22 Apr 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09036814; Issue ID: MSV-1715.

    Published: 4 Nov 2024
    4.4
    Medium

    CVE-2024-20112

    Last Modified: 22 Apr 2025

    In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20111

    Last Modified: 13 Mar 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065033; Issue ID: MSV-1754.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20110

    Last Modified: 22 Apr 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065887; Issue ID: MSV-1762.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20109

    Last Modified: 22 Apr 2025

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09065928; Issue ID: MSV-1763.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20108

    Last Modified: 22 Apr 2025

    In atci, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09082988; Issue ID: MSV-1774.

    Published: 4 Nov 2024
    6.2
    Medium

    CVE-2024-20107

    Last Modified: 24 Apr 2025

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-20106

    Last Modified: 24 Apr 2025

    In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08960505; Issue ID: MSV-1590.

    Published: 4 Nov 2024
    8.4
    High

    CVE-2024-20104

    Last Modified: 24 Apr 2025

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.

    Published: 4 Nov 2024
    6.9
    Medium

    CVE-2024-10761

    Last Modified: 22 Jan 2025

    A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} of the component Dashboard. The manipulation of the argument culture leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.8.8, 13.5.3, 14.3.2 and 15.1.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 4 Nov 2024
    5.3
    Medium

    CVE-2024-10760

    Last Modified: 5 Nov 2024

    A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Nov 2024
    5.3
    Medium

    CVE-2024-10759

    Last Modified: 5 Nov 2024

    A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The manipulation of the argument pigno/weight/arrived/breed/remark/status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "pigno" to be affected. But it must be assumed that other parameters are affected as well.

    Published: 4 Nov 2024
    8.4
    High

    CVE-2024-48336

    Last Modified: 15 Apr 2026

    The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation.

    Published: 4 Nov 2024
    5.1
    Medium

    CVE-2024-45185

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS protocol.

    Published: 4 Nov 2024
    6.1
    Medium

    CVE-2024-48057

    Last Modified: 4 Sept 2025

    localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.

    Published: 4 Nov 2024
    8
    High

    CVE-2024-51246

    Last Modified: 11 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

    Published: 4 Nov 2024
    9.8
    Critical

    CVE-2024-51327

    Last Modified: 6 Nov 2024

    SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-30619

    Last Modified: 18 Apr 2025

    Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."

    Published: 4 Nov 2024
    8.8
    High

    CVE-2024-30616

    Last Modified: 18 Apr 2025

    Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.

    Published: 4 Nov 2024
    5.4
    Medium

    CVE-2024-30617

    Last Modified: 18 Apr 2025

    A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.

    Published: 4 Nov 2024
    6.1
    Medium

    CVE-2024-30618

    Last Modified: 18 Apr 2025

    A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.

    Published: 4 Nov 2024
    4.9
    Medium

    CVE-2024-34882

    Last Modified: 6 Nov 2024

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.

    Published: 4 Nov 2024
    4.9
    Medium

    CVE-2024-34883

    Last Modified: 6 Nov 2024

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.

    Published: 4 Nov 2024
    4.9
    Medium

    CVE-2024-34887

    Last Modified: 6 Nov 2024

    Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

    Published: 4 Nov 2024
    6.8
    Medium

    CVE-2024-34885

    Last Modified: 4 Sept 2025

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

    Published: 4 Nov 2024
    6.8
    Medium

    CVE-2024-34891

    Last Modified: 4 Sept 2025

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.

    Published: 4 Nov 2024
    7.1
    High

    CVE-2024-45164

    Last Modified: 6 Nov 2024

    Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can navigate directly to the /#app/intelligence/threatAvertPolicies URI and disable policy enforcement.

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45882

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45884

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45885

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45887

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45888

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45889

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45890

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45891

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

    Published: 4 Nov 2024
    8
    High

    CVE-2024-45893

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`

    Published: 4 Nov 2024
    9.8
    Critical

    CVE-2024-48050

    Last Modified: 4 Sept 2025

    In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.

    Published: 4 Nov 2024
    6.5
    Medium

    CVE-2024-48052

    Last Modified: 13 Jun 2025

    In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

    Published: 4 Nov 2024
    9.8
    Critical

    CVE-2024-48061

    Last Modified: 27 Mar 2026

    langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

    Published: 4 Nov 2024
    6.1
    Medium

    CVE-2024-48059

    Last Modified: 11 Jul 2025

    gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malicious JavaScript is executed in the victim's browser.

    Published: 4 Nov 2024