CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-8310

    Last Modified: 15 Apr 2026

    OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

    Published: 27 Sept 2024
    7.1
    High

    CVE-2024-9284

    Last Modified: 15 Jul 2025

    A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    9.3
    Critical

    CVE-2024-8630

    Last Modified: 16 Oct 2024

    Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.

    Published: 27 Sept 2024
    9.3
    Critical

    CVE-2024-6981

    Last Modified: 15 Apr 2026

    OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

    Published: 27 Sept 2024
    5
    Medium

    CVE-2024-45745

    Last Modified: 22 Sept 2025

    TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).

    Published: 27 Sept 2024
    3
    Low

    CVE-2024-45744

    Last Modified: 2 Oct 2025

    TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system access using a separate vulnerability such as CVE-2024-45745. At least version 7.1.3 is affected. Version 7.3 adds HashiCorp Vault integration that does not store external passwords locally. Version 8.3.0 warns when using plain text secrets.

    Published: 27 Sept 2024
    8.8
    High

    CVE-2024-6983

    Last Modified: 10 Jul 2025

    mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a binary file and execute malicious code. This can lead to the attacker gaining full control over the system.

    Published: 27 Sept 2024
    6.5
    Medium

    CVE-2024-47077

    Last Modified: 21 Aug 2025

    authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were legitimately issued for one application and use it to access another application that they aren't allowed to access. Anyone who has more than one proxy provider application with different trust domains or different access control is affected. Versions 2024.8.3 and 2024.6.5 fix the issue.

    Published: 27 Sept 2024
    9
    Critical

    CVE-2024-47070

    Last Modified: 21 Aug 2025

    authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any account with a known login or email address. The vulnerability requires the authentik instance to trust X-Forwarded-For header provided by the attacker, thus it is not reproducible from external hosts on a properly configured environment. The issue occurs due to the password stage having a policy bound to it, which skips the password stage if the Identification stage is setup to also contain a password stage. Due to the invalid X-Forwarded-For header, which does not get validated to be an IP Address early enough, the exception happens later and the policy fails. The default blueprint doesn't correctly set `failure_result` to `True` on the policy binding meaning that due to this exception the policy returns false and the password stage is skipped. Versions 2024.8.3 and 2024.6.5 fix this issue.

    Published: 27 Sept 2024
    9.2
    Critical

    CVE-2024-3373

    Last Modified: 3 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection. This issue affects Website Template: before 1.2.

    Published: 27 Sept 2024
    6.1
    Medium

    CVE-2024-47184

    Last Modified: 4 Oct 2024

    Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes this issue.

    Published: 27 Sept 2024
    4.8
    Medium

    CVE-2024-9283

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 27 Sept 2024
    4.8
    Medium

    CVE-2024-47182

    Last Modified: 4 Oct 2024

    Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.

    Published: 27 Sept 2024
    8.8
    High

    CVE-2024-7149

    Last Modified: 8 Apr 2026

    The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 27 Sept 2024
    5.3
    Medium

    CVE-2024-45863

    Last Modified: 15 Apr 2026

    A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.

    Published: 27 Sept 2024
    7.5
    High

    CVE-2024-45773

    Last Modified: 15 Apr 2026

    A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.

    Published: 27 Sept 2024
    6.9
    Medium

    CVE-2024-9282

    Last Modified: 20 Aug 2025

    A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    6.9
    Medium

    CVE-2024-9281

    Last Modified: 20 Aug 2025

    A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    8.7
    High

    CVE-2024-8607

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection. This issue affects ValeApp: before v2.0.0.

    Published: 27 Sept 2024
    7.2
    High

    CVE-2024-8608

    Last Modified: 2 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS. This issue affects ValeApp: before v2.0.0.

    Published: 27 Sept 2024
    5.1
    Medium

    CVE-2024-9280

    Last Modified: 4 Oct 2024

    A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

    Published: 27 Sept 2024
    8.8
    High

    CVE-2024-8609

    Last Modified: 2 Jun 2026

    Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects ValeApp: before v2.0.0.

    Published: 27 Sept 2024
    9.3
    Critical

    CVE-2024-8643

    Last Modified: 2 Jun 2026

    Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

    Published: 27 Sept 2024
    9.3
    Critical

    CVE-2024-8644

    Last Modified: 2 Jun 2026

    Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.

    Published: 27 Sept 2024
    5.1
    Medium

    CVE-2024-9279

    Last Modified: 4 Oct 2024

    A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of the component User Center. The manipulation of the argument User Nickname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    5.1
    Medium

    CVE-2024-9278

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of the file WxkConfig.php of the component Administrator Backend. The manipulation of the argument domain_verification_file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Sept 2024
    5.1
    Medium

    CVE-2024-9277

    Last Modified: 5 Jun 2025

    A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipulation of the argument remaining_text leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    5.3
    Medium

    CVE-2024-9276

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of the argument console/nocache/cmd leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Sept 2024
    5.3
    Medium

    CVE-2024-9275

    Last Modified: 15 Apr 2026

    A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Sept 2024
    6.7
    Medium

    CVE-2024-9136

    Last Modified: 18 Sept 2025

    Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 27 Sept 2024
    4.4
    Medium

    CVE-2024-47294

    Last Modified: 1 Oct 2024

    Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 27 Sept 2024
    4.7
    Medium

    CVE-2024-47293

    Last Modified: 1 Oct 2024

    Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 27 Sept 2024
    6.2
    Medium

    CVE-2024-47292

    Last Modified: 1 Oct 2024

    Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 27 Sept 2024
    5.6
    Medium

    CVE-2024-47291

    Last Modified: 1 Oct 2024

    Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 27 Sept 2024
    5.5
    Medium

    CVE-2024-47290

    Last Modified: 1 Oct 2024

    Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 27 Sept 2024
    5.3
    Medium

    CVE-2024-9202

    Last Modified: 9 Jan 2025

    In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to request a single dataset, which should be subject to the same filtering process, but currently is missing the correct filtering. This enables parties to potentially see datasets they should not have access to, thereby exposing sensitive information. Exploiting this vulnerability requires knowing the ID of a restricted dataset, but some IDs may be guessed by trying out many IDs in an automated way. Affected code: DatasetResolverImpl, L76-79 https://github.com/eclipse-edc/Connector/blob/v0.9.0/core/control-plane/control-plane-catalog/src/main/java/org/eclipse/edc/connector/controlplane/catalog/DatasetResolverImpl.java

    Published: 27 Sept 2024
    6.1
    Medium

    CVE-2024-41930

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

    Published: 27 Sept 2024
    6.8
    Medium

    CVE-2024-6654

    Last Modified: 15 Apr 2026

    Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of the ESET security product and cause general system slow-down.

    Published: 27 Sept 2024
    7.2
    High

    CVE-2024-6931

    Last Modified: 8 Apr 2026

    The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Sept 2024
    4.9
    Medium

    CVE-2024-38861

    Last Modified: 20 Dec 2024

    Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a.

    Published: 27 Sept 2024
    6.5
    Medium

    CVE-2024-39435

    Last Modified: 30 Sept 2024

    In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 27 Sept 2024
    6.2
    Medium

    CVE-2024-39434

    Last Modified: 30 Sept 2024

    In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

    Published: 27 Sept 2024
    6.2
    Medium

    CVE-2024-39433

    Last Modified: 30 Sept 2024

    In drm service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

    Published: 27 Sept 2024
    8.3
    High

    CVE-2024-39432

    Last Modified: 30 Sept 2024

    In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.

    Published: 27 Sept 2024
    8.3
    High

    CVE-2024-39431

    Last Modified: 30 Sept 2024

    In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.

    Published: 27 Sept 2024
    8.5
    High

    CVE-2024-7400

    Last Modified: 15 Apr 2026

    The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

    Published: 27 Sept 2024
    6.4
    Medium

    CVE-2024-8681

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, and including, 4.10.52 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Sept 2024
    6.4
    Medium

    CVE-2024-8991

    Last Modified: 8 Apr 2026

    The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Sept 2024
    6.4
    Medium

    CVE-2024-9049

    Last Modified: 8 Apr 2026

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Sept 2024
    7.5
    High

    CVE-2024-9029

    Last Modified: 8 Aug 2025

    A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked to the library, resulting in a denial of service.

    Published: 27 Sept 2024