CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2024-6787

    Last Modified: 30 Sept 2024

    This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious code and potentially cause file losses.

    Published: 21 Sept 2024
    6
    Medium

    CVE-2024-6786

    Last Modified: 30 Sept 2024

    The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.

    Published: 21 Sept 2024
    6.8
    Medium

    CVE-2024-6785

    Last Modified: 27 Sept 2024

    The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

    Published: 21 Sept 2024
    8.8
    High

    CVE-2024-47210

    Last Modified: 15 Apr 2026

    Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

    Published: 21 Sept 2024
    9.8
    Critical

    CVE-2024-47219

    Last Modified: 28 Apr 2025

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

    Published: 21 Sept 2024
    —
    Unknown

    CVE-2024-9063

    Last Modified: 25 Sept 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2143 Reason: This candidate is a reservation duplicate of CVE-2023-2143. Notes: All CVE users should reference CVE-2023-2143 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 20 Sept 2024
    4.8
    Medium

    CVE-2024-45793

    Last Modified: 15 Apr 2026

    Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The following endpoints are subject to a cross site scripting vulnerability: GET /v1/credentials, GET /v1/credentials/, GET /v1/archive/credentials/, GET /v1/archive/credentials, POST /v1/credentials, PUT /v1/credentials/, PUT /v1/credentials//<to_revision>, GET /v1/services, GET /v1/services/, GET /v1/archive/services/, GET /v1/archive/services, PUT /v1/services/, PUT /v1/services//<to_revision>. The attacker needs to be authenticated and have privileges to create new credentials, but could use this to show information and run scripts to other users into the same Confidant instance. This issue has been patched in version 6.6.2. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 20 Sept 2024
    8.3
    High

    CVE-2024-47061

    Last Modified: 15 Apr 2026

    Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` property. These attributes are passed to the node component using the `nodeProps` prop. It has come to our attention that this feature can be used for malicious purposes, including cross-site scripting (XSS) and information exposure (specifically, users' IP addresses and whether or not they have opened a malicious document). Note that the risk of information exposure via attributes is only relevant to applications in which web requests to arbitrary URLs are not ordinarily allowed. Plate editors that allow users to embed images from arbitrary URLs, for example, already carry the risk of leaking users' IP addresses to third parties. All Plate editors using an affected version of @udecode/plate-core are vulnerable to these information exposure attacks via the style attribute and other attributes that can cause web requests to be sent. In addition, whether or not a Plate editor is vulnerable to cross-site scripting attacks using attributes depends on a number of factors. The most likely DOM attributes to be vulnerable are href and src on links and iframes respectively. Any component that spreads {...nodeProps} onto an <a> or <iframe> element and does not later override href or src will be vulnerable to XSS. In patched versions of Plate, we have disabled element.attributes and leaf.attributes for most attribute names by default, with some exceptions including target, alt, width, height, colspan and rowspan on the link, image, video, table cell and table header cell plugins. If this is a breaking change for you, you can selectively re-enable attributes for certain plugins as follows. Please carefully research and assess the security implications of any attribute you allow, as even seemingly innocuous attributes such as style can be used maliciously. If you are unable to upgrade to any of the patched versions, you should use a tool like patch-package or yarn patch to remove the logic from @udecode/plate-core that adds attributes to nodeProps.

    Published: 20 Sept 2024
    9.4
    Critical

    CVE-2024-47062

    Last Modified: 26 Aug 2025

    Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furthermore, the names of the parameters are not properly escaped, leading to SQL Injections. Finally, the username is used in a `LIKE` statement, allowing people to log in with `%` instead of their username. When adding parameters to the URL, they are automatically included in an SQL `LIKE` statement (depending on the parameter's name). This allows attackers to potentially retrieve arbitrary information. For example, attackers can use the following request to test whether some encrypted passwords start with `AAA`. This results in an SQL query like `password LIKE 'AAA%'`, allowing attackers to slowly brute-force passwords. When adding parameters to the URL, they are automatically added to an SQL query. The names of the parameters are not properly escaped. This behavior can be used to inject arbitrary SQL code (SQL Injection). These vulnerabilities can be used to leak information and dump the contents of the database and have been addressed in release version 0.53.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 20 Sept 2024
    6.5
    Medium

    CVE-2024-42351

    Last Modified: 15 Aug 2025

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 20 Sept 2024
    7.6
    High

    CVE-2024-42346

    Last Modified: 15 Aug 2025

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 20 Sept 2024
    6.6
    Medium

    CVE-2024-45229

    Last Modified: 25 Aug 2026

    The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by injecting invalid arguments into a GET request, potentially exposing the authentication tokens of other currently logged-in users. These tokens can then be used to invoke additional APIs on port 9183. This exploit does not disclose any username or password information. Currently, there are no workarounds in Versa Director. However, if there is Web Application Firewall (WAF) or API Gateway fronting the Versa Director, it can be used to block access to the URLs of vulnerable API. /vnms/devicereg/device/* (on ports 9182 & 9183) and /versa/vnms/devicereg/device/* (on port 443). Versa recommends that Directors be upgraded to one of the remediated software versions. This vulnerability is not exploitable on Versa Directors not exposed to the Internet.We have validated that no Versa-hosted head ends have been affected by this vulnerability. Please contact Versa Technical Support or Versa account team for any further assistance.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9041

    Last Modified: 27 Sept 2024

    A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=update_account. The manipulation of the argument firstname/lastname/email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    4.6
    Medium

    CVE-2024-9040

    Last Modified: 27 Sept 2024

    A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack has to be approached locally.

    Published: 20 Sept 2024
    6.9
    Medium

    CVE-2024-9039

    Last Modified: 27 Sept 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=signup. The manipulation of the argument firstname/lastname/email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9038

    Last Modified: 27 Sept 2024

    A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    6.9
    Medium

    CVE-2024-9037

    Last Modified: 26 Sept 2025

    A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9036

    Last Modified: 26 Sept 2025

    A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    6.9
    Medium

    CVE-2024-9035

    Last Modified: 26 Sept 2025

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Admin Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    6.9
    Medium

    CVE-2024-9034

    Last Modified: 26 Sept 2025

    A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9033

    Last Modified: 27 Sept 2024

    A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_category. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9032

    Last Modified: 20 Sept 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9031

    Last Modified: 25 Sept 2024

    A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the file /project/task/{task_id}/show. The manipulation of the argument comment leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9030

    Last Modified: 25 Sept 2024

    A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the argument notes leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-9043

    Last Modified: 25 Sept 2024

    Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing authentication and obtaining system administrator privileges.

    Published: 20 Sept 2024
    8.1
    High

    CVE-2024-41721

    Last Modified: 15 Apr 2026

    An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-8853

    Last Modified: 8 Apr 2026

    The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

    Published: 20 Sept 2024
    5.3
    Medium

    CVE-2024-9011

    Last Modified: 25 Sept 2024

    A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Sept 2024
    3.8
    Low

    CVE-2024-8612

    Last Modified: 15 Apr 2026

    A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak.

    Published: 20 Sept 2024
    4.8
    Medium

    CVE-2024-46654

    Last Modified: 28 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-46652

    Last Modified: 17 Mar 2025

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

    Published: 20 Sept 2024
    7.5
    High

    CVE-2024-46645

    Last Modified: 16 Apr 2025

    eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-45489

    Last Modified: 15 Apr 2026

    Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

    Published: 20 Sept 2024
    4.8
    Medium

    CVE-2024-37879

    Last Modified: 15 Apr 2026

    Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".

    Published: 20 Sept 2024
    8.4
    High

    CVE-2023-47480

    Last Modified: 15 Apr 2026

    An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

    Published: 20 Sept 2024
    6.5
    Medium

    CVE-2024-46647

    Last Modified: 16 Apr 2025

    eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.

    Published: 20 Sept 2024
    7.5
    High

    CVE-2024-46648

    Last Modified: 16 Apr 2025

    eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

    Published: 20 Sept 2024
    7.5
    High

    CVE-2024-46649

    Last Modified: 16 Apr 2025

    eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

    Published: 20 Sept 2024
    6.1
    Medium

    CVE-2024-42697

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-46101

    Last Modified: 28 Apr 2025

    GDidees CMS <= v3.9.1 has a file upload vulnerability.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-46103

    Last Modified: 4 Apr 2025

    SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

    Published: 20 Sept 2024
    6.5
    Medium

    CVE-2024-46646

    Last Modified: 16 Apr 2025

    eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

    Published: 20 Sept 2024
    9.8
    Critical

    CVE-2024-46640

    Last Modified: 28 Mar 2025

    SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.

    Published: 20 Sept 2024
    6.5
    Medium

    CVE-2024-46644

    Last Modified: 16 Apr 2025

    eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

    Published: 20 Sept 2024
    6.5
    Medium

    CVE-2024-45806

    Last Modified: 15 Oct 2024

    Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or other malicious actions within the mesh. This issue arises due to Envoy's default configuration of internal trust boundaries, which considers all RFC1918 private address ranges as internal. The default behavior for handling internal addresses in Envoy has been changed. Previously, RFC1918 IP addresses were automatically considered internal, even if the internal_address_config was empty. The default configuration of Envoy will continue to trust internal addresses while in this release and it will not trust them by default in next release. If you have tooling such as probes on your private network which need to be treated as trusted (e.g. changing arbitrary x-envoy headers) please explicitly include those addresses or CIDR ranges into `internal_address_config`. Successful exploitation could allow attackers to bypass security controls, access sensitive data, or disrupt services within the mesh, like Istio. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    7.5
    High

    CVE-2024-45807

    Last Modified: 25 Sept 2024

    Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the codec. To resolve this Envoy will switch off the `oghttp2` by default. The impact of this issue is that envoy will crash. This issue has been addressed in release version 1.31.2. All users are advised to upgrade. There are no known workarounds for this issue.

    Published: 19 Sept 2024
    6.5
    Medium

    CVE-2024-45808

    Last Modified: 25 Sept 2024

    Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of validation for the `REQUESTED_SERVER_NAME` field for access loggers. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-45809

    Last Modified: 24 Sept 2024

    Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remote JWKs are used, which requires async header processing; 2. clear_route_cache is enabled on the provider; 3. header operations are enabled in JWT filter, e.g. header to claims feature; 4. the routing table is configured in a way that the JWT header operations modify requests to not match any route. When these conditions are met, a crash is triggered in the upstream code due to nullptr reference conversion from route(). The root cause is the ordering of continueDecoding and clearRouteCache. This issue has been addressed in versions 1.31.2, 1.30.6, and 1.29.9. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    6.5
    Medium

    CVE-2024-45810

    Last Modified: 30 Jan 2026

    Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and requests mirroring. The http async client will crash during the `sendLocalReply()` in http async client, one reason is http async client is duplicating the status code, another one is the destroy of router is called at the destructor of the async stream, while the stream is deferred deleted at first. There will be problems that the stream decoder is destroyed but its reference is called in `router.onDestroy()`, causing segment fault. This will impact ext_authz if the `upgrade` and `connection` header are allowed, and request mirrorring. This issue has been addressed in versions 1.31.2, 1.30.6, 1.29.9, and 1.28.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9009

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file showtest.php. The manipulation of the argument subid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Sept 2024