CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2024-44744

    Last Modified: 15 Apr 2026

    An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users.

    Published: 1 Oct 2024
    5.6
    Medium

    CVE-2024-44610

    Last Modified: 15 Apr 2026

    PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.

    Published: 1 Oct 2024
    6.8
    Medium

    CVE-2021-37577

    Last Modified: 15 Apr 2026

    Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue to CVE-2020-26558.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46276

    Last Modified: 14 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46274

    Last Modified: 18 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.

    Published: 1 Oct 2024
    5.4
    Medium

    CVE-2024-46083

    Last Modified: 28 Apr 2025

    Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.

    Published: 1 Oct 2024
    9.8
    Critical

    CVE-2024-41276

    Last Modified: 15 Apr 2026

    A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.

    Published: 1 Oct 2024
    4.8
    Medium

    CVE-2024-31835

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name parameter.

    Published: 1 Oct 2024
    7.2
    High

    CVE-2024-25659

    Last Modified: 3 Jul 2025

    In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.

    Published: 1 Oct 2024
    4.7
    Medium

    CVE-2024-9407

    Last Modified: 15 Apr 2026

    A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.

    Published: 1 Oct 2024
    6.5
    Medium

    CVE-2024-25658

    Last Modified: 22 Nov 2024

    Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.

    Published: 1 Oct 2024
    9
    Critical

    CVE-2024-25660

    Last Modified: 3 Jul 2025

    The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

    Published: 1 Oct 2024
    7.7
    High

    CVE-2024-25661

    Last Modified: 4 Oct 2024

    In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.

    Published: 1 Oct 2024
    8.1
    High

    CVE-2024-42514

    Last Modified: 30 May 2025

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.

    Published: 1 Oct 2024
    4.7
    Medium

    CVE-2024-45967

    Last Modified: 6 May 2025

    Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.

    Published: 1 Oct 2024
    9.8
    Critical

    CVE-2024-45999

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.

    Published: 1 Oct 2024
    6.1
    Medium

    CVE-2024-46079

    Last Modified: 28 Apr 2025

    Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.

    Published: 1 Oct 2024
    8
    High

    CVE-2024-46080

    Last Modified: 28 Apr 2025

    Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

    Published: 1 Oct 2024
    5.4
    Medium

    CVE-2024-46081

    Last Modified: 28 Apr 2025

    Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.

    Published: 1 Oct 2024
    5.4
    Medium

    CVE-2024-46082

    Last Modified: 28 Apr 2025

    Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.

    Published: 1 Oct 2024
    8
    High

    CVE-2024-46084

    Last Modified: 28 Apr 2025

    Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46267

    Last Modified: 18 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46258

    Last Modified: 14 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46259

    Last Modified: 18 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46261

    Last Modified: 17 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46263

    Last Modified: 18 Mar 2025

    cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.

    Published: 1 Oct 2024
    7.8
    High

    CVE-2024-46264

    Last Modified: 13 Mar 2025

    cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

    Published: 1 Oct 2024
    8.7
    High

    CVE-2024-9194

    Last Modified: 2 Jul 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before 2024.3.12766.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-45073

    Last Modified: 7 Jan 2025

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 30 Sept 2024
    6.5
    Medium

    CVE-2024-9355

    Last Modified: 21 Sept 2026

    A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7675

    Last Modified: 26 Aug 2025

    A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7674

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7673

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7672

    Last Modified: 26 Aug 2025

    A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7671

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-7670

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-47536

    Last Modified: 25 Aug 2025

    Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.

    Published: 30 Sept 2024
    8.4
    High

    CVE-2024-9158

    Last Modified: 7 Oct 2024

    A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

    Published: 30 Sept 2024
    5.1
    Medium

    CVE-2024-47067

    Last Modified: 13 Feb 2026

    AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.

    Published: 30 Sept 2024
    8.7
    High

    CVE-2024-47532

    Last Modified: 15 Nov 2024

    RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.

    Published: 30 Sept 2024
    4.6
    Medium

    CVE-2024-47531

    Last Modified: 15 Nov 2024

    Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.

    Published: 30 Sept 2024
    5.4
    Medium

    CVE-2024-47530

    Last Modified: 15 Nov 2024

    Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via next parameter due to absence of sanitization logic. Additionally, due to lack of scheme validation, HTTPS Downgrade Attack can be performed on the users. This vulnerability is fixed in 4.89.

    Published: 30 Sept 2024
    8.7
    High

    CVE-2024-47178

    Last Modified: 15 Nov 2024

    basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.

    Published: 30 Sept 2024
    5.4
    Medium

    CVE-2024-47172

    Last Modified: 30 Oct 2024

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in this way is the same as the information returned on a GET request to the resource. In addition, the attacker can also alter the default source and target storage associated with any project or task. Upgrade to CVAT 2.19.1 or any later version to fix the issue.

    Published: 30 Sept 2024
    6.3
    Medium

    CVE-2024-47064

    Last Modified: 30 Oct 2024

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the victim user has access to. Upgrade to CVAT 2.19.0 or a later version to fix this issue.

    Published: 30 Sept 2024
    6.2
    Medium

    CVE-2024-47063

    Last Modified: 30 Oct 2024

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the attacker temporary access to all data that the victim user has access to. Upgrade to CVAT 2.19.0 or a later version to fix this issue.

    Published: 30 Sept 2024
    5.3
    Medium

    CVE-2024-45792

    Last Modified: 15 Aug 2025

    Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about other users' personal system profiles. This vulnerability is fixed in 2.26.4.

    Published: 30 Sept 2024
    4.3
    Medium

    CVE-2024-6051

    Last Modified: 15 Apr 2026

    Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.

    Published: 30 Sept 2024
    6.5
    Medium

    CVE-2024-47641

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel Confetti Fall Animation confetti-fall-animation allows Stored XSS.This issue affects Confetti Fall Animation: from n/a through <= 1.3.0.

    Published: 30 Sept 2024
    5.1
    Medium

    CVE-2024-45772

    Last Modified: 15 May 2025

    Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator.nrt package is not affected. Users are recommended to upgrade to version 9.12.0, which fixes the issue. The deserialization can only be triggered if users actively deploy an network-accessible implementation and a corresponding client using a HTTP library that uses the API (e.g., a custom servlet and HTTPClient). Java serialization filters (such as -Djdk.serialFilter='!*' on the commandline) can mitigate the issue on vulnerable versions without impacting functionality.

    Published: 30 Sept 2024