CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-41514

    Last Modified: 2 Jun 2025

    A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.

    Published: 4 Oct 2024
    9.8
    Critical

    CVE-2023-26770

    Last Modified: 27 May 2025

    TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

    Published: 4 Oct 2024
    6.5
    Medium

    CVE-2023-26771

    Last Modified: 27 May 2025

    Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.

    Published: 4 Oct 2024
    6.1
    Medium

    CVE-2024-47854

    Last Modified: 17 Oct 2025

    An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

    Published: 4 Oct 2024
    8.8
    High

    CVE-2024-37868

    Last Modified: 8 Oct 2024

    File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.

    Published: 4 Oct 2024
    8.8
    High

    CVE-2024-37869

    Last Modified: 8 Oct 2024

    File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable

    Published: 4 Oct 2024
    3.9
    Low

    CVE-2024-41511

    Last Modified: 2 Jun 2025

    A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter.

    Published: 4 Oct 2024
    8.8
    High

    CVE-2024-41512

    Last Modified: 2 Jun 2025

    A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.

    Published: 4 Oct 2024
    5.4
    Medium

    CVE-2024-41513

    Last Modified: 2 Jun 2025

    A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter.

    Published: 4 Oct 2024
    5.4
    Medium

    CVE-2024-41515

    Last Modified: 2 Jun 2025

    A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.

    Published: 4 Oct 2024
    5.4
    Medium

    CVE-2024-41516

    Last Modified: 2 Jun 2025

    A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.

    Published: 4 Oct 2024
    5.9
    Medium

    CVE-2024-44439

    Last Modified: 15 Apr 2026

    An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port.

    Published: 4 Oct 2024
    5.4
    Medium

    CVE-2024-46077

    Last Modified: 28 Apr 2025

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

    Published: 4 Oct 2024
    7.5
    High

    CVE-2024-46078

    Last Modified: 23 Apr 2025

    itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.

    Published: 4 Oct 2024
    5.4
    Medium

    CVE-2024-46409

    Last Modified: 3 Jul 2025

    A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.

    Published: 4 Oct 2024
    8
    High

    CVE-2024-46486

    Last Modified: 15 Aug 2025

    TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

    Published: 4 Oct 2024
    5.3
    Medium

    CVE-2024-47855

    Last Modified: 15 Apr 2026

    util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.

    Published: 4 Oct 2024
    7.2
    High

    CVE-2024-47910

    Last Modified: 15 Apr 2026

    An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.

    Published: 4 Oct 2024
    4.3
    Medium

    CVE-2024-44207

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

    Published: 3 Oct 2024
    5.5
    Medium

    CVE-2024-44204

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver.

    Published: 3 Oct 2024
    8.7
    High

    CVE-2024-42417

    Last Modified: 8 Oct 2024

    Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

    Published: 3 Oct 2024
    9.3
    Critical

    CVE-2024-43699

    Last Modified: 8 Oct 2024

    Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.

    Published: 3 Oct 2024
    9.3
    Critical

    CVE-2024-45367

    Last Modified: 15 Apr 2026

    The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.

    Published: 3 Oct 2024
    9.3
    Critical

    CVE-2024-41925

    Last Modified: 15 Apr 2026

    The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code.

    Published: 3 Oct 2024
    4.7
    Medium

    CVE-2024-9266

    Last Modified: 15 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

    Published: 3 Oct 2024
    9.3
    Critical

    CVE-2024-41988

    Last Modified: 15 Apr 2026

    TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.

    Published: 3 Oct 2024
    8.6
    High

    CVE-2024-41987

    Last Modified: 15 Apr 2026

    The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

    Published: 3 Oct 2024
    5.8
    Medium

    CVE-2024-47762

    Last Modified: 15 Apr 2026

    Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007, where unexpectedly ignoring the visibility defined in configuration schema. This occurred even if the configuration schema specified that they should have backend or secret visibility. This was an intended feature of the APP_CONFIG_* way of supplying configuration, but now clearly goes against the expected behavior of the configuration system. This behavior leads to a risk of potentially exposing sensitive configuration details intended to remain private or restricted to backend processes. The issue has been resolved in version 0.3.75 of the @backstage/plugin-app-backend package. As a temporary measure, avoid supplying secrets using the APP_CONFIG_ configuration pattern. Consider alternative methods for setting secrets, such as the environment substitution available for Backstage configuration.

    Published: 3 Oct 2024
    9.8
    Critical

    CVE-2024-7824

    Last Modified: 30 Oct 2024

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

    Published: 3 Oct 2024
    9.8
    Critical

    CVE-2024-7825

    Last Modified: 30 Oct 2024

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

    Published: 3 Oct 2024
    9.8
    Critical

    CVE-2024-7826

    Last Modified: 30 Oct 2024

    Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.

    Published: 3 Oct 2024
    3.3
    Low

    CVE-2024-0125

    Last Modified: 18 Sept 2025

    NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.

    Published: 3 Oct 2024
    3.3
    Low

    CVE-2024-0124

    Last Modified: 18 Sept 2025

    NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.

    Published: 3 Oct 2024
    3.3
    Low

    CVE-2024-0123

    Last Modified: 18 Sept 2025

    NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.

    Published: 3 Oct 2024
    5.3
    Medium

    CVE-2024-8508

    Last Modified: 17 Dec 2024

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. The vulnerability can be exploited by a malicious actor querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. Unbound version 1.21.1 introduces a hard limit on the number of name compression calculations it is willing to do per packet. Packets that need more compression will result in semi-compressed packets or truncated packets, even on TCP for huge messages, to avoid locking the CPU for long. This change should not affect normal DNS traffic.

    Published: 3 Oct 2024
    7.5
    High

    CVE-2024-25590

    Last Modified: 15 Apr 2026

    An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.

    Published: 3 Oct 2024
    8.4
    High

    CVE-2024-42415

    Last Modified: 3 Nov 2025

    An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 3 Oct 2024
    8.4
    High

    CVE-2024-36474

    Last Modified: 3 Nov 2025

    An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 3 Oct 2024
    7.5
    High

    CVE-2024-41163

    Last Modified: 18 Dec 2024

    A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 3 Oct 2024
    7.8
    High

    CVE-2024-39755

    Last Modified: 4 Sept 2025

    A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 3 Oct 2024
    7.5
    High

    CVE-2024-41922

    Last Modified: 18 Dec 2024

    A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 3 Oct 2024
    5.3
    Medium

    CVE-2024-47211

    Last Modified: 15 Apr 2026

    In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when configured to convert images to a raw format for streaming.

    Published: 3 Oct 2024
    6.9
    Medium

    CVE-2024-9460

    Last Modified: 8 Oct 2024

    A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Oct 2024
    7.5
    High

    CVE-2024-47614

    Last Modified: 15 Apr 2026

    async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10.

    Published: 3 Oct 2024
    6.1
    Medium

    CVE-2024-47617

    Last Modified: 8 Oct 2024

    Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site Scripting (XSS) issue, which could potentially allow attackers to steal sensitive information, manipulate the website's content, or perform actions on behalf of the victim. This vulnerability is fixed in 2.6.5 and 2.5.21.

    Published: 3 Oct 2024
    7.5
    High

    CVE-2024-5803

    Last Modified: 15 Apr 2026

    The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.

    Published: 3 Oct 2024
    5.1
    Medium

    CVE-2024-47618

    Last Modified: 18 Oct 2024

    Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers. This issue is fixed in 2.6.5.

    Published: 3 Oct 2024
    6.5
    Medium

    CVE-2024-9100

    Last Modified: 15 Apr 2026

    Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

    Published: 3 Oct 2024
    4.3
    Medium

    CVE-2024-47554

    Last Modified: 31 Jan 2025

    Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

    Published: 3 Oct 2024
    8.8
    High

    CVE-2024-9313

    Last Modified: 26 Aug 2025

    Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them.

    Published: 3 Oct 2024