CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-9333

    Last Modified: 15 Apr 2026

    Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation

    Published: 2 Oct 2024
    6.9
    Medium

    CVE-2024-9174

    Last Modified: 23 Feb 2026

    Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI

    Published: 2 Oct 2024
    4.5
    Medium

    CVE-2024-21530

    Last Modified: 15 Apr 2026

    Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with the same cocoon object. **Note:** The issue does NOT affect objects created with Cocoon::new which utilizes ThreadRng.

    Published: 2 Oct 2024
    8.8
    High

    CVE-2024-7855

    Last Modified: 8 Apr 2026

    The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 2 Oct 2024
    6.4
    Medium

    CVE-2024-45965

    Last Modified: 13 Nov 2025

    Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

    Published: 2 Oct 2024
    5.4
    Medium

    CVE-2024-33209

    Last Modified: 14 Mar 2025

    FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

    Published: 2 Oct 2024
    9.8
    Critical

    CVE-2024-24116

    Last Modified: 10 Feb 2025

    An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

    Published: 2 Oct 2024
    9.8
    Critical

    CVE-2024-24117

    Last Modified: 13 Mar 2025

    Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

    Published: 2 Oct 2024
    3.3
    Low

    CVE-2024-24122

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.

    Published: 2 Oct 2024
    5.4
    Medium

    CVE-2024-33210

    Last Modified: 3 Jul 2025

    A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.

    Published: 2 Oct 2024
    7.5
    High

    CVE-2024-33662

    Last Modified: 21 May 2025

    Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

    Published: 2 Oct 2024
    8.1
    High

    CVE-2024-41290

    Last Modified: 23 Apr 2025

    FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

    Published: 2 Oct 2024
    9.8
    Critical

    CVE-2024-45186

    Last Modified: 15 Apr 2026

    FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

    Published: 2 Oct 2024
    4.8
    Medium

    CVE-2024-45964

    Last Modified: 3 Jul 2025

    Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

    Published: 2 Oct 2024
    4.8
    Medium

    CVE-2024-45960

    Last Modified: 3 Jul 2025

    Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

    Published: 2 Oct 2024
    4.7
    Medium

    CVE-2024-45962

    Last Modified: 29 Sept 2025

    October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.

    Published: 2 Oct 2024
    8.8
    High

    CVE-2024-46626

    Last Modified: 17 Jul 2025

    OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

    Published: 2 Oct 2024
    10
    Critical

    CVE-2024-45519

    Last Modified: 3 Feb 2026

    The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

    Published: 2 Oct 2024
    7.5
    High

    CVE-2024-47523

    Last Modified: 7 Oct 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary JavaScript through the "Details" section (which contains multiple fields depending on which transport is selected at that moment). This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. This vulnerability is fixed in 24.9.0.

    Published: 1 Oct 2024
    7.2
    High

    CVE-2024-47524

    Last Modified: 19 Dec 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user input in the Device Groups name, when user see the detail of the Device Group, if java script code is inside the name of the Device Groups, its will be trigger. This vulnerability is fixed in 24.9.0.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-47525

    Last Modified: 7 Oct 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary JavaScript through the "Title" field. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. This vulnerability is fixed in 24.9.0.

    Published: 1 Oct 2024
    3.5
    Low

    CVE-2024-47526

    Last Modified: 19 Dec 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-47527

    Last Modified: 7 Oct 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary JavaScript through the device name ("hostname" parameter). This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions. This vulnerability is fixed in 24.9.0.

    Published: 1 Oct 2024
    4.6
    Medium

    CVE-2024-47528

    Last Modified: 19 Dec 2024

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this allow the upload of SVG file that can contain XSS payload which will trigger on load. This led to Stored Cross-Site Scripting (XSS). The vulnerability is fixed in 24.9.0.

    Published: 1 Oct 2024
    6.9
    Medium

    CVE-2024-47609

    Last Modified: 15 Apr 2026

    Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

    Published: 1 Oct 2024
    5.3
    Medium

    CVE-2024-9411

    Last Modified: 13 Nov 2025

    A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Oct 2024
    6.9
    Medium

    CVE-2024-47608

    Last Modified: 7 Oct 2024

    Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2.

    Published: 1 Oct 2024
    5.4
    Medium

    CVE-2024-9341

    Last Modified: 11 Aug 2026

    A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

    Published: 1 Oct 2024
    6.8
    Medium

    CVE-2024-47071

    Last Modified: 15 Apr 2026

    OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in 14.0.4.

    Published: 1 Oct 2024
    8.2
    High

    CVE-2024-47604

    Last Modified: 13 Nov 2024

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.

    Published: 1 Oct 2024
    8.2
    High

    CVE-2024-47534

    Last Modified: 15 Apr 2026

    go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the delegations "B"->"C"->"A". This vulnerability is fixed in 2.0.1.

    Published: 1 Oct 2024
    6.5
    Medium

    CVE-2024-9391

    Last Modified: 4 Apr 2025

    A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

    Published: 1 Oct 2024
    5.3
    Medium

    CVE-2024-9395

    Last Modified: 4 Apr 2025

    A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

    Published: 1 Oct 2024
    7.3
    High

    CVE-2024-9403

    Last Modified: 31 Mar 2025

    Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.

    Published: 1 Oct 2024
    9.8
    Critical

    CVE-2024-9401

    Last Modified: 3 Nov 2025

    Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    9.8
    Critical

    CVE-2024-9402

    Last Modified: 4 Apr 2025

    Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-9399

    Last Modified: 14 Mar 2025

    A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    8.8
    High

    CVE-2024-9396

    Last Modified: 4 Apr 2025

    It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    5.3
    Medium

    CVE-2024-9398

    Last Modified: 18 Mar 2025

    By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    8.8
    High

    CVE-2024-9400

    Last Modified: 4 Apr 2025

    A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    6.1
    Medium

    CVE-2024-9397

    Last Modified: 2 Mar 2026

    A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-9393

    Last Modified: 3 Nov 2025

    An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-9394

    Last Modified: 3 Nov 2025

    An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    9.8
    Critical

    CVE-2024-9392

    Last Modified: 3 Nov 2025

    A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

    Published: 1 Oct 2024
    7.1
    High

    CVE-2024-41673

    Last Modified: 15 Apr 2026

    Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability is fixed in 0.27.8.

    Published: 1 Oct 2024
    7.5
    High

    CVE-2024-45408

    Last Modified: 4 Oct 2024

    eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (something disabled by default), this extends to anyone. Users are advised to upgrade to at least version 5.1.0. System administrators can disable anonymous access in the System configuration panel.

    Published: 1 Oct 2024
    8.6
    High

    CVE-2024-25632

    Last Modified: 15 Aug 2025

    eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A user may be an administrator in one team and a regular user in another. The vulnerability allows a regular user to become administrator of a team where they are a member, under a reasonable configuration. Additionally, in eLabFTW versions subsequent to v5.0.0, the vulnerability may allow an initially unauthenticated user to gain administrative privileges over an arbitrary team. The vulnerability does not affect system administrator status. Users should upgrade to version 5.1.0. System administrators are advised to turn off local user registration, saml_team_create and not allow administrators to import users into teams, unless strictly required.

    Published: 1 Oct 2024
    6.8
    Medium

    CVE-2023-7273

    Last Modified: 15 Apr 2026

    Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header value to null, meaning that the existing CSRF check is bypassed in this case. An attacker can, for example, create a new administrator account if the request is executed in the browser of an authenticated victim.

    Published: 1 Oct 2024
    3.7
    Low

    CVE-2024-30132

    Last Modified: 30 Oct 2025

    HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2024
    5.3
    Medium

    CVE-2024-9405

    Last Modified: 15 Apr 2026

    An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or subdirectory as the module, but not from recursive directories.

    Published: 1 Oct 2024