CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-46942

    Last Modified: 14 Mar 2025

    In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.

    Published: 15 Sept 2024
    7.5
    High

    CVE-2024-46943

    Last Modified: 14 Mar 2025

    An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

    Published: 15 Sept 2024
    5.3
    Medium

    CVE-2024-8863

    Last Modified: 20 Sept 2024

    A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Sept 2024
    6.9
    Medium

    CVE-2024-8862

    Last Modified: 20 Sept 2024

    A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument query leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Sept 2024
    8.8
    High

    CVE-2024-6482

    Last Modified: 8 Apr 2026

    The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40. The login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49.

    Published: 14 Sept 2024
    5.4
    Medium

    CVE-2023-3410

    Last Modified: 8 Apr 2026

    The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Bricks Builder (admin-only by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This becomes more of an issue when Bricks Builder access is granted to lower-privileged users.

    Published: 14 Sept 2024
    6.1
    Medium

    CVE-2024-8797

    Last Modified: 8 Apr 2026

    The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 14 Sept 2024
    9.1
    Critical

    CVE-2024-8669

    Last Modified: 8 Apr 2026

    The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Sept 2024
    9.8
    Critical

    CVE-2024-8039

    Last Modified: 15 Apr 2026

    Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

    Published: 14 Sept 2024
    6.1
    Medium

    CVE-2024-8724

    Last Modified: 8 Apr 2026

    The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 14 Sept 2024
    7.3
    High

    CVE-2024-8479

    Last Modified: 27 Sept 2024

    The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 14 Sept 2024
    8.8
    High

    CVE-2024-8246

    Last Modified: 8 Apr 2026

    The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.

    Published: 14 Sept 2024
    7.3
    High

    CVE-2024-8271

    Last Modified: 8 Apr 2026

    The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the 'woocs_get_custom_price_html' function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 14 Sept 2024
    5.3
    Medium

    CVE-2022-3459

    Last Modified: 8 Apr 2026

    The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.

    Published: 14 Sept 2024
    4.4
    Medium

    CVE-2024-44096

    Last Modified: 15 Oct 2024

    there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.8
    High

    CVE-2024-44095

    Last Modified: 15 Oct 2024

    In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.8
    High

    CVE-2024-44094

    Last Modified: 18 Sept 2024

    In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.8
    High

    CVE-2024-44093

    Last Modified: 18 Sept 2024

    In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.8
    High

    CVE-2024-44092

    Last Modified: 15 Sept 2025

    There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.8
    High

    CVE-2024-29779

    Last Modified: 13 Mar 2025

    there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 13 Sept 2024
    7.6
    High

    CVE-2024-6259

    Last Modified: 17 Sept 2025

    BT: HCI: adv_ext_report Improper discarding in adv_ext_report

    Published: 13 Sept 2024
    7.6
    High

    CVE-2024-6137

    Last Modified: 17 Sept 2025

    BT: Classic: SDP OOB access in get_att_search_list

    Published: 13 Sept 2024
    7.6
    High

    CVE-2024-6135

    Last Modified: 19 Sept 2024

    BT:Classic: Multiple missing buf length checks

    Published: 13 Sept 2024
    6.3
    Medium

    CVE-2024-5931

    Last Modified: 17 Sept 2025

    BT: Unchecked user input in bap_broadcast_assistant

    Published: 13 Sept 2024
    6.8
    Medium

    CVE-2024-6258

    Last Modified: 17 Sept 2025

    BT: Missing length checks of net_buf in rfcomm_handle_data

    Published: 13 Sept 2024
    8.2
    High

    CVE-2024-5754

    Last Modified: 17 Sept 2025

    BT: Encryption procedure host vulnerability

    Published: 13 Sept 2024
    5.3
    Medium

    CVE-2024-8784

    Last Modified: 19 Sept 2024

    A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the component Chat. The manipulation of the argument users[] with the input 1'+AND+(SELECT+3220+FROM+(SELECT(SLEEP(5)))ZNun)+AND+'WwBM'%3d'WwBM as part of POST Request Parameter leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 13 Sept 2024
    5.3
    Medium

    CVE-2024-8783

    Last Modified: 19 Sept 2024

    A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Handler. The manipulation of the argument post_topic leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as bf6ae3df0d32fa22552bb44ca4f8489a6e78cc1c. It is recommended to apply a patch to fix this issue.

    Published: 13 Sept 2024
    5.3
    Medium

    CVE-2024-8782

    Last Modified: 19 Sept 2024

    A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Sept 2024
    6.7
    Medium

    CVE-2024-45105

    Last Modified: 15 Apr 2026

    An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 13 Sept 2024
    6.3
    Medium

    CVE-2024-45104

    Last Modified: 13 Dec 2024

    A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

    Published: 13 Sept 2024
    4.3
    Medium

    CVE-2024-45103

    Last Modified: 13 Dec 2024

    A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

    Published: 13 Sept 2024
    6.8
    Medium

    CVE-2024-45101

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.

    Published: 13 Sept 2024
    7.2
    High

    CVE-2024-8281

    Last Modified: 15 Apr 2026

    An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.

    Published: 13 Sept 2024
    7.2
    High

    CVE-2024-8280

    Last Modified: 15 Apr 2026

    An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.

    Published: 13 Sept 2024
    7.2
    High

    CVE-2024-8279

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

    Published: 13 Sept 2024
    7.2
    High

    CVE-2024-8278

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.

    Published: 13 Sept 2024
    4.3
    Medium

    CVE-2024-8059

    Last Modified: 15 Apr 2026

    IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.

    Published: 13 Sept 2024
    6.8
    Medium

    CVE-2024-7756

    Last Modified: 15 Apr 2026

    A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.

    Published: 13 Sept 2024
    6.7
    Medium

    CVE-2024-4550

    Last Modified: 15 Apr 2026

    A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 13 Sept 2024
    6.7
    Medium

    CVE-2024-3100

    Last Modified: 15 Apr 2026

    A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacker with elevated privileges to execute arbitrary code.

    Published: 13 Sept 2024
    5.6
    Medium

    CVE-2024-31416

    Last Modified: 26 Aug 2025

    The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory consumption or integer overflow.

    Published: 13 Sept 2024
    6.3
    Medium

    CVE-2024-31415

    Last Modified: 26 Aug 2025

    The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely stored, which could be abused to possibly change or remove the server configuration.

    Published: 13 Sept 2024
    6.7
    Medium

    CVE-2024-31414

    Last Modified: 19 Sept 2024

    The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.

    Published: 13 Sept 2024
    8.7
    High

    CVE-2024-45368

    Last Modified: 15 Apr 2026

    The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E PLC's protocol execution, namely its acceptance of multiple distinct packets as valid authentication responses. This behavior deviates from standard security practices where a single, specific response or encoding pattern is expected for successful authentication.

    Published: 13 Sept 2024
    8.7
    High

    CVE-2024-43099

    Last Modified: 15 Apr 2026

    The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To successfully achieve this, the attacker also needs to spoof both the IP address and MAC address of the originating host which is typical of a session-based attack.

    Published: 13 Sept 2024
    8.1
    High

    CVE-2024-6862

    Last Modified: 19 Sept 2024

    A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user with local access. The main attack vector is for instances hosted locally on personal machines, which are not publicly accessible. The CORS settings in the backend permit all origins, exposing unauthenticated endpoints to CSRF attacks.

    Published: 13 Sept 2024
    6.5
    Medium

    CVE-2024-6867

    Last Modified: 19 Sept 2024

    An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endpoint. This endpoint does not verify that the user has the necessary access rights to the run(s) they are accessing. As a result, it returns not only the specified run but also all runs that have the `run_id` listed as their parent run. This issue affects the main branch, commit a761d833. The vulnerability allows unauthorized users to obtain information about non-public runs and their related runs, given the `run_id` of a public or non-public run.

    Published: 13 Sept 2024
    6.5
    Medium

    CVE-2024-6087

    Last Modified: 15 Oct 2025

    An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an attacker to use the auth tokens issued by the 'invite user' functionality to obtain valid JWT tokens. These tokens can be used to compromise target users upon registration for their own arbitrary organizations. The attacker can invite a target email, obtain a one-time use token, retract the invite, and later use the token to reset the password of the target user, leading to full account takeover.

    Published: 13 Sept 2024
    4.3
    Medium

    CVE-2024-6582

    Last Modified: 3 Nov 2024

    A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user from one organization to update the Identity Provider (IDP) settings and view the SSO metadata of another organization. This vulnerability can lead to unauthorized access and potential account takeover if the email of a user in the target organization is known.

    Published: 13 Sept 2024