CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2024-46999

    Last Modified: 24 Sept 2024

    Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. Additionally, the management and auth API always returned the state as active or did not provide any information about the state. Versions 2.62.1, 2.61.1, 2.60.2, 2.59.3, 2.58.5, 2.57.5, 2.56.6, 2.55.8, and 2.54.10 have been released which address this issue. Users are advised to upgrade. Users unable to upgrade may explicitly remove the user grants to make sure the user does not get access anymore.

    Published: 19 Sept 2024
    8.1
    High

    CVE-2024-47000

    Last Modified: 24 Sept 2024

    Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and resources. Versions 2.62.1, 2.61.1, 2.60.2, 2.59.3, 2.58.5, 2.57.5, 2.56.6, 2.55.8, and 2.54.10 have been released which address this issue. Users are advised t upgrade. Users unable to upgrade may instead of deactivating the service account, consider creating new credentials and replacing the old ones wherever they are used. This effectively prevents the deactivated service account from being utilized. Be sure to revoke all existing authentication keys associated with the service account and to rotate the service account's password.

    Published: 19 Sept 2024
    4.3
    Medium

    CVE-2024-47060

    Last Modified: 25 Sept 2024

    Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through these applications, leading to unauthorized access. Additionally, if a project was deactivated access to applications was also still possible. The issue stems from the fact that when an organization is deactivated in Zitadel, the applications associated with it do not automatically deactivate. The application lifecycle is not tightly coupled with the organization's lifecycle, leading to a situation where the organization or project is marked as inactive, but its resources remain accessible. This vulnerability allows for unauthorized access to projects and their resources, which should have been restricted post-organization deactivation. Versions 2.62.1, 2.61.1, 2.60.2, 2.59.3, 2.58.5, 2.57.5, 2.56.6, 2.55.8, and 2.54.10 have been released which address this issue. Users are advised to upgrade. Users unable to upgrade may explicitly disable the application to make sure the client is not allowed anymore.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9008

    Last Modified: 7 Mar 2025

    A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the component Comment Section. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Sept 2024
    9.8
    Critical

    CVE-2023-27584

    Last Modified: 20 Dec 2024

    Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    9.8
    Critical

    CVE-2024-46983

    Last Modified: 25 Sept 2024

    sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components. This issue is fixed by an update to the blacklist, users can upgrade to sofahessian version 3.5.5 to avoid this issue. Users unable to upgrade may maintain a blacklist themselves in the directory `external/serialize.blacklist`.

    Published: 19 Sept 2024
    5.4
    Medium

    CVE-2024-45614

    Last Modified: 3 Nov 2025

    Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 now discards any headers using underscores if the non-underscore version also exists. Effectively, allowing the proxy defined headers to always win. Users are advised to upgrade. Nginx has a underscores_in_headers configuration variable to discard these headers at the proxy level as a mitigation. Any users that are implicitly trusting the proxy defined headers for security should immediately cease doing so until upgraded to the fixed versions.

    Published: 19 Sept 2024
    8.6
    High

    CVE-2024-46984

    Last Modified: 25 Sept 2024

    The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the referencevalidator commons package is vulnerable to `XML External Entities` attack due to insecure defaults of the used Woodstox WstxInputFactory. A malicious XML resource can lead to network requests issued by referencevalidator and thus to a `Server Side Request Forgery` attack. The vulnerability impacts applications which use referencevalidator to process XML resources from untrusted sources. The problem has been patched with the 2.5.1 version of the referencevalidator. Users are strongly recommended to update to this version or a more recent one. A pre-processing or manual analysis of input XML resources on existence of DTD definitions or external entities can mitigate the problem.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9007

    Last Modified: 25 Sept 2024

    A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9006

    Last Modified: 25 Sept 2024

    A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as f4a8c748ec436e5a79f91ccb6a6f73752b336aa5. It is recommended to apply a patch to fix this issue.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9004

    Last Modified: 23 Sept 2024

    A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9003

    Last Modified: 25 Sept 2024

    A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Sept 2024
    6.5
    Medium

    CVE-2024-43489

    Last Modified: 31 Dec 2024

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 19 Sept 2024
    6.5
    Medium

    CVE-2024-43496

    Last Modified: 31 Dec 2024

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 19 Sept 2024
    4.3
    Medium

    CVE-2024-38221

    Last Modified: 31 Dec 2024

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2024-9001

    Last Modified: 24 Sept 2024

    A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Sept 2024
    —
    Unknown

    CVE-2024-9015

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Sept 2024
    4.1
    Medium

    CVE-2024-47162

    Last Modified: 24 Sept 2024

    In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

    Published: 19 Sept 2024
    4.3
    Medium

    CVE-2024-47160

    Last Modified: 24 Sept 2024

    In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

    Published: 19 Sept 2024
    4.3
    Medium

    CVE-2024-47159

    Last Modified: 24 Sept 2024

    In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

    Published: 19 Sept 2024
    9.4
    Critical

    CVE-2024-8963

    Last Modified: 24 Oct 2025

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

    Published: 19 Sept 2024
    7.8
    High

    CVE-2024-38016

    Last Modified: 31 Dec 2024

    Microsoft Office Visio Remote Code Execution Vulnerability

    Published: 19 Sept 2024
    —
    Unknown

    CVE-2024-9012

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Sept 2024
    5.9
    Medium

    CVE-2024-8653

    Last Modified: 23 Sept 2024

    A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.

    Published: 19 Sept 2024
    5.9
    Medium

    CVE-2024-8652

    Last Modified: 23 Sept 2024

    A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.

    Published: 19 Sept 2024
    6.9
    Medium

    CVE-2024-8651

    Last Modified: 23 Sept 2024

    A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.

    Published: 19 Sept 2024
    —
    Unknown

    CVE-2024-9010

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-45862

    Last Modified: 30 Sept 2024

    Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.

    Published: 19 Sept 2024
    9.2
    Critical

    CVE-2024-45861

    Last Modified: 30 Sept 2024

    Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.

    Published: 19 Sept 2024
    5.7
    Medium

    CVE-2024-8375

    Last Modified: 22 Jul 2025

    There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C++. When a tensor proto of type VARIANT is unpacked, memory is first allocated to store the entire tensor, and a ctor is called on each instance. Afterwards, Reverb copies the content in tensor_content to the previously mentioned pre-allocated memory, which results in the bytes in tensor_content overwriting the vtable pointers of all the objects which were previously allocated. Reverb exposes 2 relevant gRPC endpoints: InsertStream and SampleStream. The attacker can insert this stream into the server’s database, then when the client next calls SampleStream they will unpack the tensor into RAM, and when any method on that object is called (including its destructor) the attacker gains control of the Program Counter. We recommend upgrading past git commit  https://github.com/google-deepmind/reverb/commit/6a0dcf4c9e842b7f999912f792aaa6f6bd261a25

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-7737

    Last Modified: 15 Apr 2026

    A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-7736

    Last Modified: 22 Oct 2025

    A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 19 Sept 2024
    6.1
    Medium

    CVE-2024-8883

    Last Modified: 1 Apr 2026

    A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

    Published: 19 Sept 2024
    7.7
    High

    CVE-2024-8698

    Last Modified: 15 Apr 2026

    A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

    Published: 19 Sept 2024
    7.4
    High

    CVE-2024-7207

    Last Modified: 30 Sept 2024

    Duplicate of CVE-2024-45806.

    Published: 19 Sept 2024
    9.8
    Critical

    CVE-2024-45410

    Last Modified: 25 Sept 2024

    Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify these headers. Since the application trusts the value of these headers, security implications might arise, if they can be modified. For HTTP/1.1, however, it was found that some of theses custom headers can indeed be removed and in certain cases manipulated. The attack relies on the HTTP/1.1 behavior, that headers can be defined as hop-by-hop via the HTTP Connection header. This issue has been addressed in release versions 2.11.9 and 3.1.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 19 Sept 2024
    9.3
    Critical

    CVE-2024-7785

    Last Modified: 3 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Software Electronic Ticket System allows Reflected XSS, Cross-Site Scripting (XSS). This issue affects Electronic Ticket System: before 2024.08.

    Published: 19 Sept 2024
    9.1
    Critical

    CVE-2024-8986

    Last Modified: 15 Apr 2026

    The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-47089

    Last Modified: 26 Sept 2024

    This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating the transaction token ID in the API request leading to unauthorized access and modification of transactions belonging to other users.

    Published: 19 Sept 2024
    9.3
    Critical

    CVE-2024-47088

    Last Modified: 26 Sept 2024

    This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on login OTP, which could lead to gain unauthorized access to other user accounts.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-47087

    Last Modified: 26 Sept 2024

    This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-47086

    Last Modified: 26 Sept 2024

    This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by providing arbitrary OTP value for authentication and subsequently changing its API response. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for other user accounts.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-47085

    Last Modified: 26 Sept 2024

    This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.

    Published: 19 Sept 2024
    6.4
    Medium

    CVE-2024-8364

    Last Modified: 8 Apr 2026

    The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and including, 1.2.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Sept 2024
    5.3
    Medium

    CVE-2022-4533

    Last Modified: 8 Apr 2026

    The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.

    Published: 19 Sept 2024
    6.1
    Medium

    CVE-2024-8850

    Last Modified: 25 Sept 2024

    The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 19 Sept 2024
    8.7
    High

    CVE-2024-7254

    Last Modified: 26 Sept 2025

    Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.

    Published: 19 Sept 2024
    6.1
    Medium

    CVE-2024-25673

    Last Modified: 19 Mar 2025

    Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

    Published: 19 Sept 2024
    9.8
    Critical

    CVE-2024-40125

    Last Modified: 25 Sept 2024

    An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.

    Published: 19 Sept 2024
    9.8
    Critical

    CVE-2024-46946

    Last Modified: 16 Jul 2025

    langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6 (2023-10-05).

    Published: 19 Sept 2024