CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-8491

    Last Modified: 16 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Sept 2024
    5.7
    Medium

    CVE-2024-42491

    Last Modified: 3 Nov 2025

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with `.1` or `[.1]`, and res_resolver_unbound is loaded, Asterisk will crash with a SEGV. To receive a patch, users should upgrade to one of the following versions: 18.24.3, 20.9.3, 21.4.3, certified-18.9-cert12, certified-20.7-cert2. Two workarounds are available. Disable res_resolver_unbound by setting `noload = res_resolver_unbound.so` in modules.conf, or set `rewrite_contact = yes` on all PJSIP endpoints. NOTE: This may not be appropriate for all Asterisk configurations.

    Published: 5 Sept 2024
    10
    Critical

    CVE-2024-7591

    Last Modified: 18 Feb 2025

    Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

    Published: 5 Sept 2024
    7.5
    High

    CVE-2024-45401

    Last Modified: 2 Jan 2025

    stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

    Published: 5 Sept 2024
    7.7
    High

    CVE-2024-45392

    Last Modified: 6 Sept 2024

    SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.

    Published: 5 Sept 2024
    9.3
    Critical

    CVE-2024-24759

    Last Modified: 6 Sept 2024

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

    Published: 5 Sept 2024
    5.9
    Medium

    CVE-2024-45097

    Last Modified: 6 Sept 2024

    IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

    Published: 5 Sept 2024
    6.5
    Medium

    CVE-2024-45096

    Last Modified: 6 Sept 2024

    IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

    Published: 5 Sept 2024
    6.8
    Medium

    CVE-2024-45098

    Last Modified: 6 Sept 2024

    IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-8473

    Last Modified: 6 Sept 2024

    Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-8472

    Last Modified: 6 Sept 2024

    Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-8471

    Last Modified: 6 Sept 2024

    Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.

    Published: 5 Sept 2024
    7.5
    High

    CVE-2024-7884

    Last Modified: 12 Sept 2024

    When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple references to be held for this internal state and not all references were dropped before the Future is resolved. Since we have unaccounted references held, a copy of the internal state ended up being persisted in the canister's heap and thus causing a memory leak. Impact Canisters built in Rust with ic_cdk and ic_cdk_timers are affected. If these canisters call a canister method, use timers or heartbeat, they will likely leak a small amount of memory on every such operation. In the worst case, this could lead to heap memory exhaustion triggered by an attacker. Motoko based canisters are not affected by the bug. PatchesThe patch has been backported to all minor versions between >= 0.8.0, <= 0.15.0. The patched versions available are 0.8.2, 0.9.3, 0.10.1, 0.11.6, 0.12.2, 0.13.5, 0.14.1, 0.15.1 and their previous versions have been yanked. WorkaroundsThere are no known workarounds at the moment. Developers are recommended to upgrade their canister as soon as possible to the latest available patched version of ic_cdk to avoid running out of Wasm heap memory. Upgrading the canisters (without updating `ic_cdk`) also frees the leaked memory but it's only a temporary solution.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-8462

    Last Modified: 15 Apr 2026

    A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8470

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8469

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8468

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8467

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8466

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8465

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.8
    Critical

    CVE-2024-8464

    Last Modified: 6 Sept 2024

    SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.

    Published: 5 Sept 2024
    9.9
    Critical

    CVE-2024-8463

    Last Modified: 12 Sept 2024

    File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

    Published: 5 Sept 2024
    6.9
    Medium

    CVE-2024-8461

    Last Modified: 12 Sept 2024

    A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-8460

    Last Modified: 6 Sept 2024

    A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality of the file /cgi-bin/widget_api.cgi of the component Web Management Interface. The manipulation of the argument getHD/getSer/getSys leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

    Published: 5 Sept 2024
    5.3
    Medium

    CVE-2022-4529

    Last Modified: 8 Apr 2026

    The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.

    Published: 5 Sept 2024
    5.3
    Medium

    CVE-2024-7381

    Last Modified: 8 Apr 2026

    The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.

    Published: 5 Sept 2024
    4.3
    Medium

    CVE-2024-7380

    Last Modified: 8 Apr 2026

    The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete WordPress menus.

    Published: 5 Sept 2024
    4.4
    Medium

    CVE-2022-3556

    Last Modified: 8 Apr 2026

    The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 5 Sept 2024
    4.3
    Medium

    CVE-2024-7605

    Last Modified: 8 Apr 2026

    The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions up to, and including, 1.1.10. This makes it possible for authenticated attackers, with Contributor-level access and above, to update plugin options, potentially disrupting the service.

    Published: 5 Sept 2024
    6.3
    Medium

    CVE-2024-5957

    Last Modified: 6 Sept 2024

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

    Published: 5 Sept 2024
    6.5
    Medium

    CVE-2024-5956

    Last Modified: 6 Sept 2024

    This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly

    Published: 5 Sept 2024
    6.4
    Medium

    CVE-2024-6894

    Last Modified: 8 Apr 2026

    The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping of post metaboxes added by the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Sept 2024
    6.4
    Medium

    CVE-2024-6929

    Last Modified: 8 Apr 2026

    The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Sept 2024
    6.5
    Medium

    CVE-2024-6332

    Last Modified: 8 Apr 2026

    The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.

    Published: 5 Sept 2024
    6.6
    Medium

    CVE-2024-6840

    Last Modified: 15 Apr 2026

    An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.

    Published: 5 Sept 2024
    5.5
    Medium

    CVE-2024-45107

    Last Modified: 6 Sept 2024

    Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 5 Sept 2024
    6.4
    Medium

    CVE-2024-8363

    Last Modified: 8 Apr 2026

    The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and including, 2.02 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Sept 2024
    5.4
    Medium

    CVE-2024-5309

    Last Modified: 8 Apr 2026

    The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv, reset_settings, save_settings, save_columns_settings, get_analytics_data, get_event_logs_data, delete_submissions, and get_submissions functions in all versions up to, and including, 1.4.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple unauthorized actions. NOTE: This vulnerability is partially fixed in version 1.4.12.

    Published: 5 Sept 2024
    5.3
    Medium

    CVE-2024-6835

    Last Modified: 8 Apr 2026

    The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text data from password-protected posts using the boolean-based attack on the AJAX search form

    Published: 5 Sept 2024
    5.3
    Medium

    CVE-2024-6846

    Last Modified: 27 Aug 2025

    The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs

    Published: 5 Sept 2024
    10
    Critical

    CVE-2024-43102

    Last Modified: 21 Nov 2024

    Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early. A malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.

    Published: 5 Sept 2024
    8.2
    High

    CVE-2024-32668

    Last Modified: 21 Nov 2024

    An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

    Published: 5 Sept 2024
    8.8
    High

    CVE-2024-45063

    Last Modified: 4 Nov 2025

    The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.

    Published: 5 Sept 2024
    8.8
    High

    CVE-2024-43110

    Last Modified: 4 Nov 2025

    The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.

    Published: 5 Sept 2024
    8.8
    High

    CVE-2024-42416

    Last Modified: 4 Nov 2025

    The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.

    Published: 5 Sept 2024
    8.8
    High

    CVE-2024-8178

    Last Modified: 4 Nov 2025

    The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process. A malicious iSCSI initiator could achieve remote code execution on the iSCSI target host.

    Published: 5 Sept 2024
    8.4
    High

    CVE-2024-41928

    Last Modified: 15 Apr 2026

    Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available to the bhyve process.

    Published: 5 Sept 2024
    8.4
    High

    CVE-2024-45288

    Last Modified: 15 Apr 2026

    A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

    Published: 5 Sept 2024
    7.5
    High

    CVE-2024-45287

    Last Modified: 21 Nov 2024

    A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.

    Published: 5 Sept 2024
    8.1
    High

    CVE-2024-7627

    Last Modified: 11 Sept 2024

    The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions.

    Published: 5 Sept 2024