CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-42343

    Last Modified: 11 Sept 2024

    Loway - CWE-204: Observable Response Discrepancy

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-42342

    Last Modified: 11 Sept 2024

    Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

    Published: 8 Sept 2024
    6.1
    Medium

    CVE-2024-42341

    Last Modified: 11 Sept 2024

    Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

    Published: 8 Sept 2024
    5.3
    Medium

    CVE-2024-8574

    Last Modified: 10 Sept 2024

    A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument slaveIpList leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    8.7
    High

    CVE-2024-8573

    Last Modified: 3 Mar 2025

    A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc/week/sTime/eTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    5.3
    Medium

    CVE-2024-8572

    Last Modified: 11 Sept 2024

    A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. The manipulation of the argument alias leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.4.1 is able to address this issue. The patch is identified as 3e661cdfb4beeb9fe2ad507cdb8104c0b17d072c. It is recommended to upgrade the affected component.

    Published: 8 Sept 2024
    5.1
    Medium

    CVE-2024-8571

    Last Modified: 11 Sept 2024

    A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure through error message. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

    Published: 8 Sept 2024
    5.3
    Medium

    CVE-2024-8570

    Last Modified: 11 Sept 2024

    A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2024
    9.8
    Critical

    CVE-2024-6928

    Last Modified: 7 Oct 2024

    The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-6925

    Last Modified: 11 Sept 2024

    The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 8 Sept 2024
    9.8
    Critical

    CVE-2024-6924

    Last Modified: 11 Sept 2024

    The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 8 Sept 2024
    5.4
    Medium

    CVE-2024-6859

    Last Modified: 11 Sept 2024

    The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-6856

    Last Modified: 11 Sept 2024

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-6855

    Last Modified: 11 Sept 2024

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-6853

    Last Modified: 11 Sept 2024

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack

    Published: 8 Sept 2024
    4.3
    Medium

    CVE-2024-6852

    Last Modified: 11 Sept 2024

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 8 Sept 2024
    6.9
    Medium

    CVE-2024-8569

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file user-login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2024
    5.3
    Medium

    CVE-2024-8568

    Last Modified: 16 Sept 2024

    A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewardMapper.select of the file tmall/admin/order/1/1. The manipulation of the argument orderBy leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Sept 2024
    6.9
    Medium

    CVE-2024-8567

    Last Modified: 10 Sept 2024

    A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_deductions. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2024
    6.9
    Medium

    CVE-2024-8566

    Last Modified: 10 Sept 2024

    A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects unknown code of the file /settings.php. The manipulation of the argument error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    6.9
    Medium

    CVE-2024-8565

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /print_diseases.php. The manipulation of the argument disease/from/to leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8564

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8563

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8562

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8561

    Last Modified: 10 Sept 2024

    A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection. The attack can be launched remotely.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8560

    Last Modified: 10 Sept 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Simple Invoice Generator System 1.0. Affected is an unknown function of the file /save_invoice.php. The manipulation of the argument invoice_code/customer/cashier/total_amount/discount_percentage/discount_amount/tendered_amount leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.1
    Medium

    CVE-2024-8559

    Last Modified: 10 Sept 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    9.9
    Critical

    CVE-2024-38650

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

    Published: 7 Sept 2024
    6.5
    Medium

    CVE-2024-42021

    Last Modified: 28 Apr 2025

    An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

    Published: 7 Sept 2024
    8.8
    High

    CVE-2024-42023

    Last Modified: 28 Apr 2025

    An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

    Published: 7 Sept 2024
    8.8
    High

    CVE-2024-40718

    Last Modified: 15 Apr 2026

    A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

    Published: 7 Sept 2024
    8.3
    High

    CVE-2024-40714

    Last Modified: 1 May 2025

    An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-42022

    Last Modified: 28 Apr 2025

    An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

    Published: 7 Sept 2024
    8.8
    High

    CVE-2024-42024

    Last Modified: 28 Apr 2025

    A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.

    Published: 7 Sept 2024
    7.8
    High

    CVE-2024-40713

    Last Modified: 1 May 2025

    A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

    Published: 7 Sept 2024
    7.8
    High

    CVE-2024-40709

    Last Modified: 15 Apr 2026

    A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

    Published: 7 Sept 2024
    9.8
    Critical

    CVE-2024-40711

    Last Modified: 30 Oct 2025

    A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

    Published: 7 Sept 2024
    8.5
    High

    CVE-2024-39715

    Last Modified: 15 Apr 2026

    A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.

    Published: 7 Sept 2024
    7.8
    High

    CVE-2024-40712

    Last Modified: 1 May 2025

    A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

    Published: 7 Sept 2024
    8.5
    High

    CVE-2024-38651

    Last Modified: 15 Apr 2026

    A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.

    Published: 7 Sept 2024
    5.4
    Medium

    CVE-2024-42020

    Last Modified: 27 Oct 2024

    A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

    Published: 7 Sept 2024
    9.9
    Critical

    CVE-2024-39714

    Last Modified: 15 Apr 2026

    A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

    Published: 7 Sept 2024
    8.8
    High

    CVE-2024-40710

    Last Modified: 1 May 2025

    A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.

    Published: 7 Sept 2024
    8.1
    High

    CVE-2024-39718

    Last Modified: 8 May 2025

    An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

    Published: 7 Sept 2024
    8
    High

    CVE-2024-42019

    Last Modified: 1 May 2025

    A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.

    Published: 7 Sept 2024
    8.1
    High

    CVE-2024-36138

    Last Modified: 15 Apr 2026

    Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8558

    Last Modified: 10 Sept 2024

    A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the component Price Handler. The manipulation of the argument total leads to improper validation of specified quantity in input. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    5.3
    Medium

    CVE-2024-8557

    Last Modified: 10 Sept 2024

    A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    6.9
    Medium

    CVE-2024-8555

    Last Modified: 10 Sept 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file congratulations.php. The manipulation of the argument goto_page leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2024
    7.5
    High

    CVE-2024-40681

    Last Modified: 15 Aug 2025

    IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.

    Published: 7 Sept 2024