CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2024-8766

    Last Modified: 15 Apr 2026

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect 16 (Windows) before build 39169.

    Published: 16 Sept 2024
    6.5
    Medium

    CVE-2024-34016

    Last Modified: 15 Apr 2026

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.

    Published: 16 Sept 2024
    5
    Medium

    CVE-2024-45800

    Last Modified: 15 Apr 2026

    Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS in emails. Research discovered that the function has a few bugs which cause an mXSS exploit. Because the function allowed too many (invalid) HTML elements, it was possible (with incorrect markup) to trick the browser to "fix" the broken markup into valid markup. As a result a motivated attacker may be able to inject javascript. However, due to the default Content Security Policy the impact of the exploit is minimal. It could be possible to create an attack which leaks some data when loading images through the proxy. This way it might be possible to use the proxy to attack the local system, like with `http://localhost:5000/leak`. Another attack could be to load a JavaScript attachment of the email. This is very tricky as the email must link to every possible UID as each email has a unique UID which has a value between 1 and 18446744073709551615 **v2.38.0** and up now remove unsupported HTML elements which mitigates the issue. Users are advised to upgrade. Older versions can install an extension named "Security mXSS" as a mitigation. This will be available at the administration area at `/?admin#/packages`. **NOTE:** this extension can not "fix" malicious code in encrypted messages or (html) attachments as it can't manipulate the JavaScript code for this. It only protects normal message HTML.

    Published: 16 Sept 2024
    5.4
    Medium

    CVE-2024-39910

    Last Modified: 29 Sept 2024

    decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the attacker manages to modify the HTML before being uploaded to the server. The attacker is able to change e.g. to <svg onload=alert('XSS')> if they know how to craft these requests themselves. This issue has been addressed in release version 0.27.7. All users are advised to upgrade. Users unable to upgrade should review the user accounts that have access to the admin panel (i.e. general Administrators, and participatory space's Administrators) and remove access to them if they don't need it. Disable the "Enable rich text editor for participants" setting in the admin dashboard

    Published: 16 Sept 2024
    6.8
    Medium

    CVE-2024-32034

    Last Modified: 29 Sept 2024

    decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted. This issue has been addressed in release version 0.27.7, 0.28.2, and newer. Users are advised to upgrade. Users unable to upgrade may redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`).

    Published: 16 Sept 2024
    7.3
    High

    CVE-2024-45799

    Last Modified: 23 Apr 2025

    FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that are currently not sanitized. This allows executing arbitrary javascript code on the user's browser just by visiting the shop pages. As a result all logged in to fluxcp users can have their session info stolen. This issue has been addressed in release version 1.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Sept 2024
    7.3
    High

    CVE-2024-45801

    Last Modified: 22 Sept 2025

    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check. This renders dompurify unable to avoid cross site scripting (XSS) attacks. This issue has been addressed in versions 2.5.4 and 3.1.3 of DOMPurify. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Sept 2024
    4.6
    Medium

    CVE-2024-8661

    Last Modified: 16 Dec 2024

    Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N  Since the "Next&Previous Nav" block output was not sufficiently sanitized, the malicious payload could be executed in the browsers of targeted users. Thanks, Chu Quoc Khanh for reporting.

    Published: 16 Sept 2024
    6.8
    Medium

    CVE-2024-23984

    Last Modified: 15 Apr 2026

    Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

    Published: 16 Sept 2024
    5.6
    Medium

    CVE-2024-24968

    Last Modified: 15 Apr 2026

    Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.

    Published: 16 Sept 2024
    1.8
    Low

    CVE-2023-25546

    Last Modified: 15 Apr 2026

    Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

    Published: 16 Sept 2024
    6.8
    Medium

    CVE-2023-43753

    Last Modified: 15 Apr 2026

    Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.

    Published: 16 Sept 2024
    6.9
    Medium

    CVE-2023-22351

    Last Modified: 15 Apr 2026

    Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    6.9
    Medium

    CVE-2023-23904

    Last Modified: 15 Apr 2026

    NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    8.7
    High

    CVE-2023-41833

    Last Modified: 15 Apr 2026

    A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    7
    High

    CVE-2024-21781

    Last Modified: 15 Apr 2026

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.

    Published: 16 Sept 2024
    8.7
    High

    CVE-2024-21829

    Last Modified: 15 Apr 2026

    Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    8.7
    High

    CVE-2023-42772

    Last Modified: 15 Apr 2026

    Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    8.7
    High

    CVE-2023-43626

    Last Modified: 15 Apr 2026

    Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    7.3
    High

    CVE-2024-21871

    Last Modified: 15 Apr 2026

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    8.3
    High

    CVE-2024-23599

    Last Modified: 15 Apr 2026

    Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.

    Published: 16 Sept 2024
    3.3
    Low

    CVE-2024-28170

    Last Modified: 23 Sept 2024

    Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 16 Sept 2024
    3.5
    Low

    CVE-2024-36261

    Last Modified: 23 Sept 2024

    Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 16 Sept 2024
    4.6
    Medium

    CVE-2024-36247

    Last Modified: 23 Sept 2024

    Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 16 Sept 2024
    4.7
    Medium

    CVE-2024-32666

    Last Modified: 23 Sept 2024

    NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.

    Published: 16 Sept 2024
    5.2
    Medium

    CVE-2024-34545

    Last Modified: 23 Sept 2024

    Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.

    Published: 16 Sept 2024
    6.5
    Medium

    CVE-2024-33848

    Last Modified: 23 Sept 2024

    Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.

    Published: 16 Sept 2024
    6.5
    Medium

    CVE-2024-32940

    Last Modified: 23 Sept 2024

    Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 16 Sept 2024
    6.7
    Medium

    CVE-2024-34153

    Last Modified: 23 Sept 2024

    Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    6.7
    Medium

    CVE-2024-34543

    Last Modified: 23 Sept 2024

    Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Sept 2024
    9.3
    Critical

    CVE-2024-8752

    Last Modified: 20 Sept 2024

    The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

    Published: 16 Sept 2024
    6.3
    Medium

    CVE-2024-38315

    Last Modified: 20 Sept 2024

    IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

    Published: 16 Sept 2024
    9.2
    Critical

    CVE-2024-6401

    Last Modified: 3 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection. This issue affects InsureE GL: before 4.6.2.

    Published: 16 Sept 2024
    9.2
    Critical

    CVE-2024-7104

    Last Modified: 3 Jun 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection. This issue affects ww.Winsure: before 4.6.2.

    Published: 16 Sept 2024
    9.2
    Critical

    CVE-2024-7098

    Last Modified: 3 Jun 2026

    Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.

    Published: 16 Sept 2024
    —
    Unknown

    CVE-2024-8895

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Sept 2024
    2.5
    Low

    CVE-2024-45835

    Last Modified: 1 Nov 2024

    Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.

    Published: 16 Sept 2024
    3.7
    Low

    CVE-2024-39772

    Last Modified: 1 Nov 2024

    Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-22399

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol. This issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0. Users are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue.

    Published: 16 Sept 2024
    3.3
    Low

    CVE-2024-46970

    Last Modified: 20 Sept 2024

    In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

    Published: 16 Sept 2024
    9.1
    Critical

    CVE-2024-7387

    Last Modified: 11 Aug 2026

    A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

    Published: 16 Sept 2024
    9.9
    Critical

    CVE-2024-45496

    Last Modified: 11 Aug 2026

    A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45698

    Last Modified: 15 Sept 2025

    Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45697

    Last Modified: 19 Sept 2024

    Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.

    Published: 16 Sept 2024
    8.8
    High

    CVE-2024-45696

    Last Modified: 19 Sept 2024

    Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.

    Published: 16 Sept 2024
    4.5
    Medium

    CVE-2024-45833

    Last Modified: 23 Sept 2024

    Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..

    Published: 16 Sept 2024
    5.3
    Medium

    CVE-2024-39613

    Last Modified: 20 Sept 2024

    Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45695

    Last Modified: 17 Sept 2024

    The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45694

    Last Modified: 17 Sept 2024

    The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

    Published: 16 Sept 2024
    6.5
    Medium

    CVE-2024-8780

    Last Modified: 20 Sept 2024

    OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain accounts and password hashes of other users.

    Published: 16 Sept 2024