CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-8779

    Last Modified: 17 Sept 2024

    OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system settings or create accounts with administrator privileges, thereby gaining control of the server.

    Published: 16 Sept 2024
    6.5
    Medium

    CVE-2024-8778

    Last Modified: 20 Sept 2024

    OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.

    Published: 16 Sept 2024
    7.5
    High

    CVE-2024-8777

    Last Modified: 20 Sept 2024

    OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.

    Published: 16 Sept 2024
    6.1
    Medium

    CVE-2024-8776

    Last Modified: 17 Mar 2026

    SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.

    Published: 16 Sept 2024
    5.3
    Medium

    CVE-2024-1578

    Last Modified: 20 Sept 2024

    The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in failed login attempts for end-users. Random characters being dropped from ID card numbers compromises the uniqueness of ID cards that can, therefore, result in a security issue if the users are using the ‘ID card self-registration’ function.

    Published: 16 Sept 2024
    6.3
    Medium

    CVE-2024-8880

    Last Modified: 20 Sept 2024

    A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot of the component Template Handler. The manipulation of the argument username/email/captcha leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The project maintainer was informed early about the issue. Investigation shows that playSMS up to 1.4.3 contained a fix but later versions re-introduced the flaw. As long as the latest version of the playsms/tpl package is used, the software is not affected. Version >=1.4.4 shall fix this issue for sure.

    Published: 16 Sept 2024
    5.4
    Medium

    CVE-2024-11831

    Last Modified: 1 Sept 2026

    A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45414

    Last Modified: 15 Apr 2026

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.

    Published: 16 Sept 2024
    8.1
    High

    CVE-2024-45413

    Last Modified: 15 Apr 2026

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated attacker can get RCE as root by exploiting this vulnerability.

    Published: 16 Sept 2024
    7.5
    High

    CVE-2023-45854

    Last Modified: 15 Apr 2026

    A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

    Published: 16 Sept 2024
    9.1
    Critical

    CVE-2024-46958

    Last Modified: 13 Mar 2025

    In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.

    Published: 16 Sept 2024
    7.5
    High

    CVE-2024-46937

    Last Modified: 24 Oct 2024

    An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user tokens without authentication. The is a brute-force attack on the serial parameter by number identifier: GA00001, GA00002, GA00003, etc.

    Published: 16 Sept 2024
    4.2
    Medium

    CVE-2024-42795

    Last Modified: 28 Apr 2025

    An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-45415

    Last Modified: 15 Apr 2026

    The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack without validating it. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.

    Published: 16 Sept 2024
    8.1
    High

    CVE-2024-45416

    Last Modified: 15 Apr 2026

    The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid session file or not. An attacker who is able to write a malicious file in the sessions directory can get RCE as root.

    Published: 16 Sept 2024
    4.7
    Medium

    CVE-2024-42794

    Last Modified: 28 Apr 2025

    Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.

    Published: 16 Sept 2024
    5.9
    Medium

    CVE-2024-42796

    Last Modified: 28 Apr 2025

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.

    Published: 16 Sept 2024
    7.6
    High

    CVE-2024-42798

    Last Modified: 28 Apr 2025

    An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.

    Published: 16 Sept 2024
    —
    Unknown

    CVE-2024-44445

    Last Modified: 21 Nov 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-44623

    Last Modified: 25 Sept 2024

    An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-46419

    Last Modified: 17 Sept 2024

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.

    Published: 16 Sept 2024
    7.5
    High

    CVE-2024-46424

    Last Modified: 17 Sept 2024

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.

    Published: 16 Sept 2024
    9.8
    Critical

    CVE-2024-46451

    Last Modified: 17 Sept 2024

    TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

    Published: 16 Sept 2024
    5.3
    Medium

    CVE-2024-8876

    Last Modified: 20 Sept 2024

    A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.3.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 15 Sept 2024
    5.3
    Medium

    CVE-2024-8875

    Last Modified: 20 Sept 2024

    A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. The manipulation of the argument p leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Sept 2024
    2.3
    Low

    CVE-2024-8869

    Last Modified: 20 Sept 2024

    A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Sept 2024
    7.1
    High

    CVE-2024-44053

    Last Modified: 27 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: from n/a through 1.8.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44054

    Last Modified: 23 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Fluida allows Stored XSS.This issue affects Fluida: from n/a through 1.8.8.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44056

    Last Modified: 28 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Mantra allows Stored XSS.This issue affects Mantra: from n/a through 3.3.2.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44057

    Last Modified: 23 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Nirvana allows Stored XSS.This issue affects Nirvana: from n/a through 1.6.3.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44058

    Last Modified: 23 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through 2.4.1.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44059

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.3.1.

    Published: 15 Sept 2024
    7.1
    High

    CVE-2024-44060

    Last Modified: 27 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a through 1.1.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44062

    Last Modified: 27 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6.5.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-44063

    Last Modified: 27 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.

    Published: 15 Sept 2024
    5.9
    Medium

    CVE-2024-45455

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: from n/a through <= 4.5.13.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-45456

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP Meta SEO wp-meta-seo allows Stored XSS.This issue affects WP Meta SEO: from n/a through <= 4.5.13.

    Published: 15 Sept 2024
    6.5
    Medium

    CVE-2024-45457

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through <= 4.9.13.

    Published: 15 Sept 2024
    7.1
    High

    CVE-2024-45458

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through <= 4.9.13.

    Published: 15 Sept 2024
    7.1
    High

    CVE-2024-45459

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.50.

    Published: 15 Sept 2024
    5.9
    Medium

    CVE-2024-45460

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manu225 Flipping Cards flipping-cards allows Stored XSS.This issue affects Flipping Cards: from n/a through <= 1.30.

    Published: 15 Sept 2024
    6.9
    Medium

    CVE-2024-8868

    Last Modified: 17 Sept 2024

    A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file savedata.php. The manipulation of the argument sname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Sept 2024
    5.3
    Medium

    CVE-2024-8867

    Last Modified: 17 Sept 2024

    A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 15 Sept 2024
    6.9
    Medium

    CVE-2024-8866

    Last Modified: 20 Sept 2024

    A vulnerability was found in AutoCMS 5.4. It has been classified as problematic. This affects an unknown part of the file /admin/robot.php. The manipulation of the argument sidebar leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Sept 2024
    5.1
    Medium

    CVE-2024-8865

    Last Modified: 17 Sept 2024

    A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file composio\server\api.py. The manipulation of the argument file leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Sept 2024
    5.1
    Medium

    CVE-2024-8864

    Last Modified: 17 Sept 2024

    A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathematical/actions/calculator.py. The manipulation leads to code injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Sept 2024
    —
    Unknown

    CVE-2024-46915

    Last Modified: 16 Apr 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 15 Sept 2024
    —
    Unknown

    CVE-2024-46914

    Last Modified: 22 Oct 2024

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 15 Sept 2024
    4.9
    Medium

    CVE-2024-46918

    Last Modified: 13 Mar 2025

    app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

    Published: 15 Sept 2024
    7.5
    High

    CVE-2024-46938

    Last Modified: 20 Sept 2024

    An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

    Published: 15 Sept 2024