CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-45804

    Last Modified: 17 Sept 2024

    This CVE is a duplicate of another CVE.

    Published: 9 Sept 2024
    7.1
    High

    CVE-2024-7015

    Last Modified: 3 Jun 2026

    Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-7318

    Last Modified: 26 Jan 2026

    A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2024-7260

    Last Modified: 23 Jan 2026

    An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it redirects to a malicious server. This issue can result in a victim inadvertently trusting the destination of the redirect, potentially leading to a successful phishing attack or other types of attacks. Once a crafted URL is made, it can be sent to a Keycloak admin via email for example. This will trigger this vulnerability when the user visits the page and clicks the link. A malicious actor can use this to target users they know are Keycloak admins for further attacks. It may also be possible to bypass other domain-related security checks, such as supplying this as a OAuth redirect uri. The malicious actor can further obfuscate the redirect_uri using URL encoding, to hide the text of the actual malicious website domain.

    Published: 9 Sept 2024
    7.1
    High

    CVE-2024-7341

    Last Modified: 1 Apr 2026

    A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.

    Published: 9 Sept 2024
    6.3
    Medium

    CVE-2024-6572

    Last Modified: 25 Aug 2025

    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic

    Published: 9 Sept 2024
    8.7
    High

    CVE-2024-8601

    Last Modified: 17 Sept 2024

    This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive information belonging to other users.

    Published: 9 Sept 2024
    9.9
    Critical

    CVE-2024-37288

    Last Modified: 17 Sept 2024

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html  and have configured an Amazon Bedrock connector https://www.elastic.co/guide/en/security/current/assistant-connect-to-bedrock.html .

    Published: 9 Sept 2024
    4.3
    Medium

    CVE-2024-45203

    Last Modified: 13 Mar 2025

    Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-7918

    Last Modified: 7 Oct 2024

    The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 9 Sept 2024
    4.3
    Medium

    CVE-2024-7689

    Last Modified: 7 Oct 2024

    The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 9 Sept 2024
    6.5
    Medium

    CVE-2024-7688

    Last Modified: 7 Oct 2024

    The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

    Published: 9 Sept 2024
    4.3
    Medium

    CVE-2024-7687

    Last Modified: 7 Oct 2024

    The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-6910

    Last Modified: 7 Oct 2024

    The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 9 Sept 2024
    4.8
    Medium

    CVE-2024-5561

    Last Modified: 7 Oct 2024

    The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2024-45625

    Last Modified: 26 Mar 2025

    Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2024-8586

    Last Modified: 16 Sept 2024

    WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.

    Published: 9 Sept 2024
    6.5
    Medium

    CVE-2024-8585

    Last Modified: 11 Sept 2024

    Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-8584

    Last Modified: 21 Feb 2025

    Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2024-44085

    Last Modified: 3 Jul 2025

    ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.

    Published: 9 Sept 2024
    7.2
    High

    CVE-2024-44724

    Last Modified: 22 Apr 2025

    AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.

    Published: 9 Sept 2024
    4.4
    Medium

    CVE-2024-27365

    Last Modified: 14 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_blockack_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2023-50883

    Last Modified: 20 Sept 2024

    ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.

    Published: 9 Sept 2024
    6.1
    Medium

    CVE-2024-24510

    Last Modified: 17 Jun 2025

    Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

    Published: 9 Sept 2024
    4.4
    Medium

    CVE-2024-27366

    Last Modified: 25 Mar 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_done_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.

    Published: 9 Sept 2024
    4.4
    Medium

    CVE-2024-27367

    Last Modified: 14 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_scan_ind(), there is no input validation check on a length coming from userspace, which can lead to integer overflow and a potential heap over-read.

    Published: 9 Sept 2024
    6.7
    Medium

    CVE-2024-27387

    Last Modified: 17 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.

    Published: 9 Sept 2024
    6.3
    Medium

    CVE-2024-42759

    Last Modified: 3 Jul 2025

    An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

    Published: 9 Sept 2024
    8.8
    High

    CVE-2024-44334

    Last Modified: 15 Apr 2026

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.

    Published: 9 Sept 2024
    8.8
    High

    CVE-2024-44335

    Last Modified: 15 Apr 2026

    D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

    Published: 9 Sept 2024
    7.5
    High

    CVE-2024-44375

    Last Modified: 17 Mar 2025

    D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-44410

    Last Modified: 10 Sept 2024

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-44411

    Last Modified: 21 May 2025

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

    Published: 9 Sept 2024
    7.5
    High

    CVE-2024-44720

    Last Modified: 28 Mar 2025

    SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-44721

    Last Modified: 28 Mar 2025

    SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

    Published: 9 Sept 2024
    7.2
    High

    CVE-2024-44725

    Last Modified: 22 Apr 2025

    AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-44849

    Last Modified: 1 Jul 2025

    Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

    Published: 9 Sept 2024
    9.8
    Critical

    CVE-2024-44902

    Last Modified: 20 Sept 2024

    A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

    Published: 9 Sept 2024
    4.4
    Medium

    CVE-2024-27364

    Last Modified: 20 Mar 2025

    An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_roamed_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.

    Published: 9 Sept 2024
    4.4
    Medium

    CVE-2024-27368

    Last Modified: 18 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function slsi_rx_received_frame_ind(), there is no input validation check on a length coming from userspace, which can lead to a potential heap over-read.

    Published: 9 Sept 2024
    6.7
    Medium

    CVE-2024-27383

    Last Modified: 18 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check on default_ies coming from userspace, which can lead to a heap overwrite.

    Published: 9 Sept 2024
    8.8
    High

    CVE-2024-44333

    Last Modified: 15 Apr 2026

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp.

    Published: 9 Sept 2024
    5.3
    Medium

    CVE-2024-8583

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects an unknown part of the file /mfeedback.php of the component Feedback Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2024
    5.3
    Medium

    CVE-2024-8582

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument description leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2024
    9.2
    Critical

    CVE-2024-8580

    Last Modified: 10 Sept 2024

    A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8579

    Last Modified: 10 Sept 2024

    A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8578

    Last Modified: 9 Sept 2024

    A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument device_name leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8577

    Last Modified: 10 Sept 2024

    A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8576

    Last Modified: 10 Sept 2024

    A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8575

    Last Modified: 9 Sept 2024

    A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024