CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2024-9566

    Last Modified: 9 Oct 2024

    A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Oct 2024
    7.8
    High

    CVE-2024-43047

    Last Modified: 28 Oct 2025

    Memory corruption while maintaining memory maps of HLOS memory.

    Published: 7 Oct 2024
    6.1
    Medium

    CVE-2024-38425

    Last Modified: 16 Oct 2024

    Information disclosure while sending implicit broadcast containing APP launch information.

    Published: 7 Oct 2024
    8.4
    High

    CVE-2024-38399

    Last Modified: 16 Oct 2024

    Memory corruption while processing user packets to generate page faults.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-38397

    Last Modified: 11 Aug 2025

    Transient DOS while parsing probe response and assoc response frame.

    Published: 7 Oct 2024
    8.2
    High

    CVE-2024-33073

    Last Modified: 11 Aug 2025

    Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-33071

    Last Modified: 16 Oct 2024

    Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-33070

    Last Modified: 16 Oct 2024

    Transient DOS while parsing ESP IE from beacon/probe response frame.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-33069

    Last Modified: 16 Oct 2024

    Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-33066

    Last Modified: 16 Oct 2024

    Memory corruption while redirecting log file to any file location with any file name.

    Published: 7 Oct 2024
    8.4
    High

    CVE-2024-33065

    Last Modified: 23 Mar 2026

    Memory corruption while taking snapshot when an offset variable is set by camera driver.

    Published: 7 Oct 2024
    8.2
    High

    CVE-2024-33064

    Last Modified: 16 Oct 2024

    Information disclosure while parsing the multiple MBSSID IEs from the beacon.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-33049

    Last Modified: 11 Aug 2025

    Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23379

    Last Modified: 16 Oct 2024

    Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23378

    Last Modified: 16 Oct 2024

    Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23376

    Last Modified: 16 Oct 2024

    Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23375

    Last Modified: 16 Oct 2024

    Memory corruption during the network scan request.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23374

    Last Modified: 16 Oct 2024

    Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-23370

    Last Modified: 16 Oct 2024

    Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.

    Published: 7 Oct 2024
    7.8
    High

    CVE-2024-23369

    Last Modified: 11 Aug 2025

    Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

    Published: 7 Oct 2024
    7.8
    High

    CVE-2024-21455

    Last Modified: 11 Aug 2025

    Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-42027

    Last Modified: 15 Apr 2026

    The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.

    Published: 7 Oct 2024
    5.4
    Medium

    CVE-2024-45153

    Last Modified: 2 Dec 2024

    Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 7 Oct 2024
    5.3
    Medium

    CVE-2024-47344

    Last Modified: 23 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5.

    Published: 7 Oct 2024
    7.6
    High

    CVE-2024-47335

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11.

    Published: 7 Oct 2024
    4.9
    Medium

    CVE-2024-20102

    Last Modified: 13 Mar 2025

    In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-20099

    Last Modified: 25 Apr 2025

    In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-20098

    Last Modified: 25 Apr 2025

    In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996886; Issue ID: MSV-1626.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-20097

    Last Modified: 27 Oct 2024

    In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1630.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-20096

    Last Modified: 27 Oct 2024

    In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996900; Issue ID: MSV-1635.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-20095

    Last Modified: 27 Oct 2024

    In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08996894; Issue ID: MSV-1636.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-20094

    Last Modified: 25 Apr 2025

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-20103

    Last Modified: 24 Apr 2025

    In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-20101

    Last Modified: 24 Apr 2025

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-20100

    Last Modified: 25 Apr 2025

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-20093

    Last Modified: 27 Oct 2024

    In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1699.

    Published: 7 Oct 2024
    7.8
    High

    CVE-2024-20092

    Last Modified: 25 Apr 2025

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700.

    Published: 7 Oct 2024
    4.4
    Medium

    CVE-2024-20091

    Last Modified: 27 Oct 2024

    In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1701.

    Published: 7 Oct 2024
    6.7
    Medium

    CVE-2024-20090

    Last Modified: 25 Apr 2025

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1703.

    Published: 7 Oct 2024
    8.7
    High

    CVE-2024-9565

    Last Modified: 8 Oct 2024

    A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Oct 2024
    8.7
    High

    CVE-2024-9564

    Last Modified: 8 Oct 2024

    A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Oct 2024
    3.1
    Low

    CVE-2024-8925

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-46446

    Last Modified: 11 Oct 2024

    Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

    Published: 7 Oct 2024
    5.5
    Medium

    CVE-2024-46325

    Last Modified: 2 Jun 2025

    TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.

    Published: 7 Oct 2024
    6.1
    Medium

    CVE-2024-46300

    Last Modified: 10 Oct 2024

    itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

    Published: 7 Oct 2024
    8.4
    High

    CVE-2024-46278

    Last Modified: 4 Jun 2025

    Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

    Published: 7 Oct 2024
    8.1
    High

    CVE-2024-44068

    Last Modified: 17 Jun 2025

    An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-45873

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-45874

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.

    Published: 7 Oct 2024
    6.6
    Medium

    CVE-2024-45933

    Last Modified: 15 Apr 2026

    OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.

    Published: 7 Oct 2024