CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-7292

    Last Modified: 16 Oct 2024

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

    Published: 9 Oct 2024
    7.5
    High

    CVE-2024-7294

    Last Modified: 15 Oct 2024

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.

    Published: 9 Oct 2024
    7.5
    High

    CVE-2024-7293

    Last Modified: 15 Oct 2024

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-7840

    Last Modified: 3 Nov 2025

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47425

    Last Modified: 18 Oct 2024

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47423

    Last Modified: 18 Oct 2024

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be automatically processed or executed by the system. Exploitation of this issue requires user interaction.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47421

    Last Modified: 18 Oct 2024

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47424

    Last Modified: 18 Oct 2024

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47422

    Last Modified: 18 Oct 2024

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by inserting a malicious path into the search directories, which the application could unknowingly execute. This could allow the attacker to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-8048

    Last Modified: 3 Nov 2025

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45137

    Last Modified: 18 Oct 2024

    InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed, could run arbitrary code in the context of the server. Exploitation of this issue requires user interaction.

    Published: 9 Oct 2024
    8.8
    High

    CVE-2024-8014

    Last Modified: 3 Nov 2025

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45136

    Last Modified: 18 Oct 2024

    InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.

    Published: 9 Oct 2024
    —
    Unknown

    CVE-2024-9688

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45138

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45142

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Write-what-where Condition vulnerability that could allow an attacker to execute arbitrary code in the context of the current user. This vulnerability allows an attacker to write a controlled value to an arbitrary memory location, potentially leading to code execution. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45143

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45141

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45152

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45139

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45140

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45144

    Last Modified: 18 Oct 2024

    Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    8.8
    High

    CVE-2024-9286

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Distant Education Platform allows SQL Injection, Parameter Injection. This issue affects Distant Education Platform: before 3.2024.11.

    Published: 9 Oct 2024
    9.8
    Critical

    CVE-2024-9680

    Last Modified: 4 Nov 2025

    An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

    Published: 9 Oct 2024
    8.2
    High

    CVE-2024-45720

    Last Modified: 11 Feb 2025

    On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is processed. All versions of Subversion up to and including Subversion 1.14.3 are affected on Windows platforms only. Users are recommended to upgrade to version Subversion 1.14.4, which fixes this issue. Subversion is not affected on UNIX-like platforms.

    Published: 9 Oct 2024
    7.5
    High

    CVE-2024-28168

    Last Modified: 16 Jul 2025

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

    Published: 9 Oct 2024
    7.6
    High

    CVE-2024-47334

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1.

    Published: 9 Oct 2024
    5.5
    Medium

    CVE-2024-45145

    Last Modified: 18 Oct 2024

    Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    8.5
    High

    CVE-2024-9575

    Last Modified: 15 Apr 2026

    Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pretix Widget WordPress plugin: from 1.0.0 through 1.0.5.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47410

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47415

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47417

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47416

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    5.5
    Medium

    CVE-2024-47419

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47413

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    5.5
    Medium

    CVE-2024-47420

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47414

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47418

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47411

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-47412

    Last Modified: 10 Oct 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45146

    Last Modified: 18 Oct 2024

    Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    7.8
    High

    CVE-2024-45150

    Last Modified: 18 Oct 2024

    Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    5.5
    Medium

    CVE-2024-20787

    Last Modified: 18 Oct 2024

    Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Oct 2024
    6.4
    Medium

    CVE-2024-9451

    Last Modified: 15 Apr 2026

    The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Oct 2024
    2.9
    Low

    CVE-2024-39586

    Last Modified: 17 Oct 2024

    Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

    Published: 9 Oct 2024
    6.4
    Medium

    CVE-2024-9449

    Last Modified: 15 Apr 2026

    The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Oct 2024
    6.2
    Medium

    CVE-2024-39440

    Last Modified: 17 Oct 2024

    In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.

    Published: 9 Oct 2024
    6.2
    Medium

    CVE-2024-39439

    Last Modified: 17 Oct 2024

    In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

    Published: 9 Oct 2024
    6.5
    Medium

    CVE-2024-39438

    Last Modified: 17 Oct 2024

    In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

    Published: 9 Oct 2024
    6.5
    Medium

    CVE-2024-39437

    Last Modified: 17 Oct 2024

    In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.

    Published: 9 Oct 2024