CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-6394

    Last Modified: 9 Jul 2025

    A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary files on the server, potentially exposing sensitive information such as private SSH keys, configuration files, and source code.

    Published: 30 Sept 2024
    7.2
    High

    CVE-2024-8459

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.

    Published: 30 Sept 2024
    2.4
    Low

    CVE-2024-42496

    Last Modified: 15 Apr 2026

    Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with physical access to the device may retrieve the credential information and spoof the device to access the related external service.

    Published: 30 Sept 2024
    6.8
    Medium

    CVE-2024-41999

    Last Modified: 15 Apr 2026

    Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change the device's settings, or spoof devices in other rooms.

    Published: 30 Sept 2024
    8.8
    High

    CVE-2024-8458

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating accounts.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-8457

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

    Published: 30 Sept 2024
    9.8
    Critical

    CVE-2024-8456

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.

    Published: 30 Sept 2024
    8.1
    High

    CVE-2024-8455

    Last Modified: 4 Oct 2024

    The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.

    Published: 30 Sept 2024
    5.3
    Medium

    CVE-2024-8454

    Last Modified: 4 Oct 2024

    The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

    Published: 30 Sept 2024
    4.9
    Medium

    CVE-2024-8453

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.

    Published: 30 Sept 2024
    6.9
    Medium

    CVE-2024-9329

    Last Modified: 21 Nov 2024

    In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

    Published: 30 Sept 2024
    7.5
    High

    CVE-2024-8452

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.

    Published: 30 Sept 2024
    7.5
    High

    CVE-2024-8451

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.

    Published: 30 Sept 2024
    8.6
    High

    CVE-2024-8450

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges.

    Published: 30 Sept 2024
    6.8
    Medium

    CVE-2024-8449

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

    Published: 30 Sept 2024
    8.8
    High

    CVE-2024-8448

    Last Modified: 4 Oct 2024

    Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.

    Published: 30 Sept 2024
    5.4
    Medium

    CVE-2024-8536

    Last Modified: 3 Oct 2024

    The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 30 Sept 2024
    7.2
    High

    CVE-2024-8379

    Last Modified: 7 Oct 2024

    The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-8283

    Last Modified: 7 Oct 2024

    The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 30 Sept 2024
    5.4
    Medium

    CVE-2024-8239

    Last Modified: 7 Oct 2024

    The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-3635

    Last Modified: 2 Oct 2024

    The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 30 Sept 2024
    5.9
    Medium

    CVE-2024-8447

    Last Modified: 7 Sept 2026

    A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

    Published: 30 Sept 2024
    7.5
    High

    CVE-2024-46511

    Last Modified: 15 Apr 2026

    LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and CredsGenFunction function.

    Published: 30 Sept 2024
    7.8
    High

    CVE-2024-46869

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver private data Fix driver not allocating memory for struct btintel_data which is used to store internal data.

    Published: 30 Sept 2024
    5.9
    Medium

    CVE-2024-46635

    Last Modified: 15 Apr 2026

    An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

    Published: 30 Sept 2024
    7.6
    High

    CVE-2024-46549

    Last Modified: 15 Apr 2026

    An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.

    Published: 30 Sept 2024
    6.3
    Medium

    CVE-2024-46540

    Last Modified: 17 Jun 2025

    A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.

    Published: 30 Sept 2024
    6.3
    Medium

    CVE-2024-45200

    Last Modified: 15 Apr 2026

    In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization of session information via a malformed browse-reply packet, aka KartLANPwn. The victim is not required to join a game session with an attacker. The victim must open the "Wireless Play" (or "LAN Play") menu from the game's title screen, and an attacker nearby (LDN) or on the same LAN network as the victim can send a crafted reply packet to the victim's console. This enables a remote attacker to obtain complete denial-of-service on the game's process, or potentially, remote code execution on the victim's console. The issue is caused by incorrect use of the Nintendo Pia library,

    Published: 30 Sept 2024
    6.5
    Medium

    CVE-2024-45993

    Last Modified: 10 Jul 2025

    Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

    Published: 30 Sept 2024
    8
    High

    CVE-2024-46313

    Last Modified: 9 Jul 2025

    TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.

    Published: 30 Sept 2024
    8.8
    High

    CVE-2024-46280

    Last Modified: 15 Apr 2026

    PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.

    Published: 30 Sept 2024
    6.3
    Medium

    CVE-2024-46548

    Last Modified: 15 Apr 2026

    TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.

    Published: 30 Sept 2024
    6.5
    Medium

    CVE-2024-28807

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.

    Published: 30 Sept 2024
    8.4
    High

    CVE-2024-28813

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.

    Published: 30 Sept 2024
    2.7
    Low

    CVE-2024-28808

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.

    Published: 30 Sept 2024
    8.8
    High

    CVE-2024-28809

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.

    Published: 30 Sept 2024
    6.6
    Medium

    CVE-2024-28810

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.

    Published: 30 Sept 2024
    3.3
    Low

    CVE-2024-28811

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.

    Published: 30 Sept 2024
    8.8
    High

    CVE-2024-28812

    Last Modified: 30 May 2025

    An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.

    Published: 30 Sept 2024
    4.3
    Medium

    CVE-2024-35495

    Last Modified: 15 Apr 2026

    An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.

    Published: 30 Sept 2024
    10
    Critical

    CVE-2024-42017

    Last Modified: 15 Apr 2026

    An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.

    Published: 30 Sept 2024
    5.4
    Medium

    CVE-2024-45920

    Last Modified: 10 Jul 2025

    A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.

    Published: 30 Sept 2024
    9.8
    Critical

    CVE-2024-46293

    Last Modified: 28 Apr 2025

    Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.

    Published: 30 Sept 2024
    4.8
    Medium

    CVE-2024-46475

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

    Published: 30 Sept 2024
    7.6
    High

    CVE-2024-46510

    Last Modified: 27 May 2025

    ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface

    Published: 30 Sept 2024
    —
    Unknown

    CVE-2024-46503

    Last Modified: 10 Oct 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Sept 2024
    5.3
    Medium

    CVE-2024-9328

    Last Modified: 1 Oct 2024

    A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /control/edit_client.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Sept 2024
    5.3
    Medium

    CVE-2024-9327

    Last Modified: 2 Oct 2024

    A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot.php. The manipulation of the argument useremail leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Sept 2024
    6.9
    Medium

    CVE-2024-9326

    Last Modified: 2 Oct 2024

    A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Sept 2024
    8.5
    High

    CVE-2024-9325

    Last Modified: 4 Nov 2024

    A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol Cliente\incontrol_webcam\incontrol-service-watchdog.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. Upgrading to version 2.21.58 is able to address this issue. It is recommended to upgrade the affected component. The vendor was informed early on 2024-08-05 about this issue. The release of a fixed version 2.21.58 was announced for the end of August 2024 but then was postponed until 2024-09-20.

    Published: 29 Sept 2024