CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-44115

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application

    Published: 10 Sept 2024
    2
    Low

    CVE-2024-44114

    Last Modified: 16 Sept 2024

    SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-44113

    Last Modified: 15 Apr 2026

    Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-42380

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application.

    Published: 10 Sept 2024
    6.1
    Medium

    CVE-2024-42378

    Last Modified: 15 Apr 2026

    Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.

    Published: 10 Sept 2024
    5.4
    Medium

    CVE-2024-42371

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-41729

    Last Modified: 15 Apr 2026

    Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.

    Published: 10 Sept 2024
    7.3
    High

    CVE-2024-8478

    Last Modified: 8 Apr 2026

    The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-8268

    Last Modified: 8 Apr 2026

    The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-6342

    Last Modified: 22 Jan 2025

    **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published: 10 Sept 2024
    5.3
    Medium

    CVE-2024-38270

    Last Modified: 18 Sept 2024

    An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if multiple authenticated sessions are alive.

    Published: 10 Sept 2024
    —
    Unknown

    CVE-2024-45845

    Last Modified: 12 Sept 2024

    DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should reference CVE-2024-45593 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2023-36103

    Last Modified: 24 Sept 2024

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

    Published: 10 Sept 2024
    9.1
    Critical

    CVE-2024-43040

    Last Modified: 15 Apr 2026

    Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.

    Published: 10 Sept 2024
    7.5
    High

    CVE-2023-37232

    Last Modified: 18 Sept 2024

    Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2023-37233

    Last Modified: 18 Sept 2024

    Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2023-37234

    Last Modified: 18 Sept 2024

    Loftware Spectrum through 4.6 has unprotected JMX Registry.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2023-37231

    Last Modified: 29 May 2025

    Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2023-37226

    Last Modified: 29 May 2025

    Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2023-37227

    Last Modified: 29 May 2025

    Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2023-37229

    Last Modified: 3 Jul 2025

    Loftware Spectrum before 5.1 allows SSRF.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2023-37230

    Last Modified: 10 Jul 2025

    Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-44893

    Last Modified: 29 Sept 2025

    An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

    Published: 10 Sept 2024
    5.9
    Medium

    CVE-2024-25073

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the CC (Call Control module), which can lead to Denial of Service (Untrusted Pointer Dereference).

    Published: 10 Sept 2024
    5.9
    Medium

    CVE-2024-25074

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check a pointer specified by the SM (Session Management module), which can lead to Denial of Service (Untrusted Pointer Dereference).

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-31960

    Last Modified: 24 Sept 2024

    An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.

    Published: 10 Sept 2024
    6.1
    Medium

    CVE-2024-34831

    Last Modified: 17 Jul 2025

    cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.

    Published: 10 Sept 2024
    7.5
    High

    CVE-2024-37728

    Last Modified: 15 Apr 2026

    Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-44677

    Last Modified: 8 Apr 2025

    eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

    Published: 10 Sept 2024
    8
    High

    CVE-2024-44667

    Last Modified: 5 Jul 2026

    Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

    Published: 10 Sept 2024
    4.8
    Medium

    CVE-2024-44676

    Last Modified: 14 Apr 2025

    eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.

    Published: 10 Sept 2024
    4.6
    Medium

    CVE-2024-44815

    Last Modified: 25 Sept 2024

    Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

    Published: 10 Sept 2024
    7.5
    High

    CVE-2024-44867

    Last Modified: 10 Jul 2025

    phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

    Published: 10 Sept 2024
    7.2
    High

    CVE-2024-44871

    Last Modified: 13 Sept 2024

    An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 10 Sept 2024
    6.1
    Medium

    CVE-2024-44872

    Last Modified: 13 Sept 2024

    A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

    Published: 10 Sept 2024
    5.3
    Medium

    CVE-2024-8611

    Last Modified: 18 Sept 2024

    A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Sept 2024
    5.3
    Medium

    CVE-2024-8610

    Last Modified: 17 Sept 2024

    A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants of the component New Tenant Page. The manipulation of the argument Last Name/First Name/Middle Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Sept 2024
    8.2
    High

    CVE-2024-6796

    Last Modified: 20 Sept 2024

    In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

    Published: 9 Sept 2024
    10
    Critical

    CVE-2024-6795

    Last Modified: 20 Sept 2024

    In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.

    Published: 9 Sept 2024
    9.3
    Critical

    CVE-2024-42500

    Last Modified: 15 Apr 2026

    HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

    Published: 9 Sept 2024
    7.5
    High

    CVE-2024-45296

    Last Modified: 15 Apr 2026

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.

    Published: 9 Sept 2024
    8.5
    High

    CVE-2024-45411

    Last Modified: 21 Nov 2024

    Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

    Published: 9 Sept 2024
    5.5
    Medium

    CVE-2024-45406

    Last Modified: 13 Sept 2024

    Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

    Published: 9 Sept 2024
    6.9
    Medium

    CVE-2024-8605

    Last Modified: 13 Sept 2024

    A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration Form. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Sept 2024
    6.9
    Medium

    CVE-2024-8604

    Last Modified: 30 Mar 2026

    A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.

    Published: 9 Sept 2024
    2.4
    Low

    CVE-2024-8042

    Last Modified: 17 Sept 2024

    Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This vulnerability is remediated as of August 14, 2024.

    Published: 9 Sept 2024
    8.3
    High

    CVE-2024-45041

    Last Modified: 18 Sept 2024

    External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It also has path/update verb of validatingwebhookconfigurations resources. This can be used to abuse the SA token of the deployment to retrieve or get ALL secrets in the whole cluster, capture and log all data from requests attempting to update Secrets, or make a webhook deny all Pod create and update requests. This vulnerability is fixed in 0.10.2.

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-8373

    Last Modified: 20 Nov 2025

    Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-8372

    Last Modified: 20 Nov 2025

    Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

    Published: 9 Sept 2024
    9.6
    Critical

    CVE-2024-40643

    Last Modified: 17 Sept 2024

    Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.

    Published: 9 Sept 2024