CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2024-8983

    Last Modified: 30 Sept 2025

    Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 8 Oct 2024
    6.4
    Medium

    CVE-2024-9292

    Last Modified: 15 Apr 2026

    The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-21533

    Last Modified: 15 Apr 2026

    All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL scheme, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-21532

    Last Modified: 15 Apr 2026

    All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-9026

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

    Published: 8 Oct 2024
    5.4
    Medium

    CVE-2024-47594

    Last Modified: 14 Nov 2024

    SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking it. When a victim who is registered on the portal clicks on such link, confidentiality and integrity of their web browser session could be compromised.

    Published: 8 Oct 2024
    4.3
    Medium

    CVE-2024-45282

    Last Modified: 14 Nov 2024

    Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.

    Published: 8 Oct 2024
    5.4
    Medium

    CVE-2024-45278

    Last Modified: 14 Nov 2024

    SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

    Published: 8 Oct 2024
    4.3
    Medium

    CVE-2024-45277

    Last Modified: 14 Nov 2024

    The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.

    Published: 8 Oct 2024
    7.7
    High

    CVE-2024-37179

    Last Modified: 14 Nov 2024

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-45382

    Last Modified: 16 Oct 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-43697

    Last Modified: 16 Oct 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-43696

    Last Modified: 16 Oct 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

    Published: 8 Oct 2024
    4.4
    Medium

    CVE-2024-39831

    Last Modified: 16 Oct 2024

    in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

    Published: 8 Oct 2024
    5.5
    Medium

    CVE-2024-39806

    Last Modified: 16 Oct 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43484

    Last Modified: 9 Jun 2026

    .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43483

    Last Modified: 9 Jun 2026

    .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

    Published: 8 Oct 2024
    5.3
    Medium

    CVE-2024-9622

    Last Modified: 15 Apr 2026

    A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.

    Published: 8 Oct 2024
    5.3
    Medium

    CVE-2024-9621

    Last Modified: 15 Apr 2026

    A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.

    Published: 8 Oct 2024
    5.3
    Medium

    CVE-2024-9620

    Last Modified: 15 Apr 2026

    A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this vulnerability by reading the plaintext data stored in EDA and AAP databases.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-25885

    Last Modified: 15 Apr 2026

    An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.

    Published: 8 Oct 2024
    3.1
    Low

    CVE-2024-8928

    Last Modified: 8 Oct 2024

    A flaw was found in PHP. Erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed, violating data integrity.

    Published: 8 Oct 2024
    —
    Unknown

    CVE-2024-48261

    Last Modified: 14 Oct 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation duplicate of CVE-2024-48251. Notes: All CVE users should reference CVE-2024-48251 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 8 Oct 2024
    8
    High

    CVE-2024-45880

    Last Modified: 15 Apr 2026

    A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the system function to execute commands for setting parameters such as MAC address without proper input filtering. This allows malicious users to inject and execute arbitrary commands.

    Published: 8 Oct 2024
    8.2
    High

    CVE-2024-46539

    Last Modified: 15 Apr 2026

    Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).

    Published: 8 Oct 2024
    8.1
    High

    CVE-2024-38229

    Last Modified: 9 Jun 2026

    .NET and Visual Studio Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    5.3
    Medium

    CVE-2024-9671

    Last Modified: 20 Mar 2026

    A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.

    Published: 8 Oct 2024
    4.9
    Medium

    CVE-2024-36814

    Last Modified: 15 Apr 2026

    An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43485

    Last Modified: 9 Jun 2026

    .NET and Visual Studio Denial of Service Vulnerability

    Published: 8 Oct 2024
    9.8
    Critical

    CVE-2024-44349

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

    Published: 8 Oct 2024
    9.8
    Critical

    CVE-2024-45918

    Last Modified: 15 Apr 2026

    Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

    Published: 8 Oct 2024
    4.8
    Medium

    CVE-2024-46410

    Last Modified: 23 Apr 2025

    PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

    Published: 8 Oct 2024
    6.2
    Medium

    CVE-2024-47969

    Last Modified: 15 Apr 2026

    Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

    Published: 7 Oct 2024
    5.3
    Medium

    CVE-2024-47781

    Last Modified: 14 Nov 2024

    CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request wiki queue when requesting a wiki. If a wiki creator comes across the XSS payload, their user session can be abused to retrieve deleted wiki requests, which typically contains private information. Likewise, this can also be abused on those with the ability to suppress requests to view sensitive information. This issue has been patched with commit `693a220` and all users are advised to apply the patch. Users unable to upgrade should disable Javascript and/or prevent access to the vulnerable page (Special:RequestWikiQueue).

    Published: 7 Oct 2024
    7.6
    High

    CVE-2024-47782

    Last Modified: 14 Nov 2024

    WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. However, the special page does not make any effort to escape the wiki name or description. Therefore, if a wiki sets its name and/or description to an XSS payload, the XSS will execute whenever the wiki is shown on Special:WikiDiscover. This issue has been patched with commit `2ce846dd93` and all users are advised to apply that patch. User unable to upgrade should block access to `Special:WikiDiscover`.

    Published: 7 Oct 2024
    5.3
    Medium

    CVE-2024-47817

    Last Modified: 15 Apr 2026

    Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Users are advised to upgrade to the appropriate fix versions detailed in the advisory metadata. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-47968

    Last Modified: 15 Apr 2026

    Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service.

    Published: 7 Oct 2024
    3.9
    Low

    CVE-2024-47814

    Last Modified: 3 Nov 2025

    Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    6.5
    Medium

    CVE-2024-47818

    Last Modified: 15 Apr 2026

    Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling the `sync/clean_sync_dir` endpoint. The `dir_name` POST parameter is not validated/sanitized and is used to construct the `syncDir` that is deleted by calling `fs.rm`. This issue has been addressed in release version 1.0.0-beta16 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-47967

    Last Modified: 15 Apr 2026

    Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

    Published: 7 Oct 2024
    6.5
    Medium

    CVE-2024-47772

    Last Modified: 25 Sept 2025

    Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This issue only affects sites with CSP disabled. This problem is patched in the latest version of Discourse. All users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled on the forum. Users who do upgrade should also consider enabling a CSP as well as a proactive measure.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-47974

    Last Modified: 15 Apr 2026

    Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.

    Published: 7 Oct 2024
    7.3
    High

    CVE-2024-47610

    Last Modified: 17 Dec 2025

    InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then displayed to other logged in users who visit the same page and executed. The vulnerability has been addressed as follows: 1. HTML sanitization has been enabled in the front-end markdown rendering library - `easymde`. 2. Stored markdown is also validated on the backend, to ensure that malicious markdown is not stored in the database. These changes are available in release versions 0.16.5 and later. All users are advised to upgrade. There are no workarounds, an update is required to get the new validation functions.

    Published: 7 Oct 2024
    5.1
    Medium

    CVE-2024-47973

    Last Modified: 15 Apr 2026

    In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.

    Published: 7 Oct 2024
    7.2
    High

    CVE-2024-43363

    Last Modified: 3 Nov 2025

    Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the cacti log file. After having the malicious hostname end up in the logs (log poisoning), one can simply go to the log file url to execute commands to achieve RCE. This issue has been addressed in version 1.2.28 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    5.7
    Medium

    CVE-2024-43365

    Last Modified: 3 Nov 2025

    Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the “consolenewsection” parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    5.7
    Medium

    CVE-2024-43364

    Last Modified: 3 Nov 2025

    Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `title` parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    7.3
    High

    CVE-2024-43362

    Last Modified: 3 Nov 2025

    Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `fileurl` parameter in the http post request while creating external links to perform stored XSS attacks. The vulnerability known as XSS (Cross-Site Scripting) occurs when an application allows untrusted user input to be displayed on a web page without proper validation or escaping. This issue has been addressed in release version 1.2.28. All users are advised to upgrade. There are no known workarounds for this issue.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-43789

    Last Modified: 25 Sept 2025

    Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024
    5.3
    Medium

    CVE-2024-45297

    Last Modified: 25 Sept 2025

    Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Oct 2024