CVE Feed

    Dashboard / CVE

    9.2
    Critical

    CVE-2024-45823

    Last Modified: 2 Oct 2024

    CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.

    Published: 12 Sept 2024
    7.8
    High

    CVE-2024-6510

    Last Modified: 2 Oct 2024

    Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-42483

    Last Modified: 23 Sept 2024

    ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared resource for all kinds of messages, whether they are broadcast or unicast, and regardless of whether they are ciphertext or plaintext. This can result an attacker to clear the cache of its legitimate entries, there by creating an opportunity to re-inject previously captured packets. This vulnerability is fixed in 2.5.2.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-42484

    Last Modified: 15 Apr 2026

    ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there is no check for the addrs_num field of the group type message. This can result in memory corruption related attacks. Normally there are two fields in the group information that need to be checked, i.e., the addrs_num field and the addrs_list fileld. Since we only checked the addrs_list field, an attacker can send a group type message with an invalid addrs_num field, which will cause the message handled by the firmware to be much larger than the current buffer, thus causing a memory corruption issue that goes beyond the payload length.

    Published: 12 Sept 2024
    9.2
    Critical

    CVE-2024-45824

    Last Modified: 31 Jan 2025

    CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.

    Published: 12 Sept 2024
    —
    Unknown

    CVE-2024-8753

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Sept 2024
    9
    Critical

    CVE-2024-28991

    Last Modified: 17 Sept 2024

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

    Published: 12 Sept 2024
    6.3
    Medium

    CVE-2024-28990

    Last Modified: 16 Sept 2024

    SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-3306

    Last Modified: 3 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.

    Published: 12 Sept 2024
    9
    Critical

    CVE-2024-45856

    Last Modified: 16 Sept 2024

    A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

    Published: 12 Sept 2024
    7.1
    High

    CVE-2024-45855

    Last Modified: 16 Sept 2024

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.

    Published: 12 Sept 2024
    7.1
    High

    CVE-2024-45854

    Last Modified: 16 Sept 2024

    Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-3305

    Last Modified: 3 Jun 2026

    Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.

    Published: 12 Sept 2024
    7.1
    High

    CVE-2024-45853

    Last Modified: 16 Sept 2024

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45852

    Last Modified: 16 Sept 2024

    Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45851

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list item creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45850

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for site column creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45849

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45848

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45847

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-45846

    Last Modified: 16 Sept 2024

    An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with the Weaviate engine, the code will be passed to an eval function and executed on the server.

    Published: 12 Sept 2024
    7.8
    High

    CVE-2024-45857

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.

    Published: 12 Sept 2024
    7.8
    High

    CVE-2024-27321

    Last Modified: 20 Sept 2024

    An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

    Published: 12 Sept 2024
    7.8
    High

    CVE-2024-27320

    Last Modified: 23 Sept 2024

    An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

    Published: 12 Sept 2024
    5.4
    Medium

    CVE-2021-22503

    Last Modified: 19 Sept 2024

    Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

    Published: 12 Sept 2024
    5.8
    Medium

    CVE-2021-22518

    Last Modified: 2 Oct 2024

    A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

    Published: 12 Sept 2024
    7.6
    High

    CVE-2021-22532

    Last Modified: 19 Sept 2024

    Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2021-22533

    Last Modified: 19 Sept 2024

    Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

    Published: 12 Sept 2024
    5.4
    Medium

    CVE-2021-38131

    Last Modified: 18 Sept 2024

    Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2021-38132

    Last Modified: 18 Sept 2024

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

    Published: 12 Sept 2024
    7.4
    High

    CVE-2021-38133

    Last Modified: 18 Sept 2024

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

    Published: 12 Sept 2024
    4.9
    Medium

    CVE-2022-26322

    Last Modified: 2 Oct 2024

    Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.

    Published: 12 Sept 2024
    5.4
    Medium

    CVE-2024-8750

    Last Modified: 18 Sept 2024

    Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view).

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-8749

    Last Modified: 18 Sept 2024

    SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys_api_model_cmdb_objects_by_relation.class.php and retrieve all the information stored in the database.

    Published: 12 Sept 2024
    8.8
    High

    CVE-2024-2010

    Last Modified: 3 Jun 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS. This issue affects V5: before 6.2.

    Published: 12 Sept 2024
    10
    Critical

    CVE-2024-8522

    Last Modified: 8 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Sept 2024
    10
    Critical

    CVE-2024-8529

    Last Modified: 8 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-8622

    Last Modified: 8 Apr 2026

    The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-8056

    Last Modified: 27 Sept 2024

    The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-8054

    Last Modified: 27 Sept 2024

    The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-7862

    Last Modified: 30 Sept 2024

    The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-7861

    Last Modified: 27 Sept 2024

    The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-7860

    Last Modified: 27 Sept 2024

    The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-7859

    Last Modified: 23 Jan 2026

    The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-7822

    Last Modified: 27 Sept 2024

    The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-7820

    Last Modified: 27 Sept 2024

    The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-7818

    Last Modified: 27 Sept 2024

    The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-7817

    Last Modified: 27 Sept 2024

    The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-7816

    Last Modified: 26 Sept 2024

    The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-7766

    Last Modified: 26 Sept 2024

    The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 12 Sept 2024