CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-7012

    Last Modified: 11 Nov 2025

    An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.

    Published: 4 Sept 2024
    9.8
    Critical

    CVE-2024-7923

    Last Modified: 11 Nov 2025

    An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.

    Published: 4 Sept 2024
    7.8
    High

    CVE-2024-7834

    Last Modified: 5 Sept 2024

    A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

    Published: 4 Sept 2024
    0
    Low

    CVE-2024-8421

    Last Modified: 30 Oct 2024

    Red Hat Product Security has come to the conclusion that this CVE is not needed.

    Published: 4 Sept 2024
    5.4
    Medium

    CVE-2024-8413

    Last Modified: 5 Sept 2024

    Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially hijacking their session details. References list

    Published: 4 Sept 2024
    7.5
    High

    CVE-2024-8418

    Last Modified: 29 Jun 2026

    A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive and resulting in other DNS queries timing out. This issue prevents legitimate users from accessing DNS services, thereby disrupting normal operations and causing service downtime.

    Published: 4 Sept 2024
    9.8
    Critical

    CVE-2024-8289

    Last Modified: 8 Apr 2026

    The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability check on the update_item_permissions_check and create_item_permissions_check functions in all versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to change the password of any user with the vendor role, create new users with the vendor role, and demote other users like administrators to the vendor role.

    Published: 4 Sept 2024
    6.5
    Medium

    CVE-2024-7870

    Last Modified: 8 Apr 2026

    The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files, and to delete log files.

    Published: 4 Sept 2024
    7.5
    High

    CVE-2024-45195

    Last Modified: 23 Oct 2025

    Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

    Published: 4 Sept 2024
    9.8
    Critical

    CVE-2024-45507

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

    Published: 4 Sept 2024
    6.4
    Medium

    CVE-2024-8318

    Last Modified: 8 Apr 2026

    The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Sept 2024
    5.4
    Medium

    CVE-2024-8121

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change an admin's username to a username of their liking as long as the default 'admin' was used.

    Published: 4 Sept 2024
    5.4
    Medium

    CVE-2024-8123

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate posts written by other authors including admins. This includes the ability to duplicate password-protected posts, which reveals their contents.

    Published: 4 Sept 2024
    8.8
    High

    CVE-2024-8102

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 4 Sept 2024
    6.5
    Medium

    CVE-2024-8106

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including usernames, hashed passwords, and emails.

    Published: 4 Sept 2024
    6.1
    Medium

    CVE-2024-8119

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 4 Sept 2024
    8.8
    High

    CVE-2024-8104

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 4 Sept 2024
    6.1
    Medium

    CVE-2024-8117

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 4 Sept 2024
    5.3
    Medium

    CVE-2024-7786

    Last Modified: 27 Aug 2025

    The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

    Published: 4 Sept 2024
    9.8
    Critical

    CVE-2024-6926

    Last Modified: 7 Oct 2024

    The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

    Published: 4 Sept 2024
    4.8
    Medium

    CVE-2024-6889

    Last Modified: 7 Oct 2024

    The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 4 Sept 2024
    4.8
    Medium

    CVE-2024-6888

    Last Modified: 7 Oct 2024

    The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 4 Sept 2024
    4.8
    Medium

    CVE-2024-6722

    Last Modified: 7 Oct 2024

    The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 4 Sept 2024
    6.1
    Medium

    CVE-2024-6020

    Last Modified: 7 Oct 2024

    The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.

    Published: 4 Sept 2024
    4.3
    Medium

    CVE-2024-34661

    Last Modified: 5 Sept 2024

    Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.

    Published: 4 Sept 2024
    7.3
    High

    CVE-2024-34660

    Last Modified: 5 Sept 2024

    Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

    Published: 4 Sept 2024
    7.5
    High

    CVE-2024-34659

    Last Modified: 5 Sept 2024

    Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

    Published: 4 Sept 2024
    4
    Medium

    CVE-2024-34658

    Last Modified: 5 Sept 2024

    Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

    Published: 4 Sept 2024
    8.6
    High

    CVE-2024-34657

    Last Modified: 5 Sept 2024

    Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

    Published: 4 Sept 2024
    7.3
    High

    CVE-2024-34656

    Last Modified: 6 Sept 2024

    Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

    Published: 4 Sept 2024
    6.2
    Medium

    CVE-2024-34655

    Last Modified: 5 Sept 2024

    Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

    Published: 4 Sept 2024
    6.2
    Medium

    CVE-2024-34654

    Last Modified: 5 Sept 2024

    Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

    Published: 4 Sept 2024
    4.6
    Medium

    CVE-2024-34653

    Last Modified: 5 Sept 2024

    Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

    Published: 4 Sept 2024
    4
    Medium

    CVE-2024-34652

    Last Modified: 5 Sept 2024

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

    Published: 4 Sept 2024
    6.2
    Medium

    CVE-2024-34651

    Last Modified: 5 Sept 2024

    Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

    Published: 4 Sept 2024
    4
    Medium

    CVE-2024-34650

    Last Modified: 5 Sept 2024

    Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

    Published: 4 Sept 2024
    2.4
    Low

    CVE-2024-34649

    Last Modified: 5 Sept 2024

    Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

    Published: 4 Sept 2024
    5.1
    Medium

    CVE-2024-34648

    Last Modified: 5 Sept 2024

    Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

    Published: 4 Sept 2024
    4
    Medium

    CVE-2024-34647

    Last Modified: 5 Sept 2024

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

    Published: 4 Sept 2024
    6.6
    Medium

    CVE-2024-34646

    Last Modified: 5 Sept 2024

    Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

    Published: 4 Sept 2024
    6.1
    Medium

    CVE-2024-34645

    Last Modified: 5 Sept 2024

    Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

    Published: 4 Sept 2024
    4.4
    Medium

    CVE-2024-34644

    Last Modified: 5 Sept 2024

    Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.

    Published: 4 Sept 2024
    4.4
    Medium

    CVE-2024-34643

    Last Modified: 5 Sept 2024

    Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.

    Published: 4 Sept 2024
    4.6
    Medium

    CVE-2024-34642

    Last Modified: 5 Sept 2024

    Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

    Published: 4 Sept 2024
    5.1
    Medium

    CVE-2024-34641

    Last Modified: 6 Sept 2024

    Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

    Published: 4 Sept 2024
    3.3
    Low

    CVE-2024-34640

    Last Modified: 5 Sept 2024

    Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

    Published: 4 Sept 2024
    4.6
    Medium

    CVE-2024-34639

    Last Modified: 5 Sept 2024

    Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

    Published: 4 Sept 2024
    6.7
    Medium

    CVE-2024-34638

    Last Modified: 5 Sept 2024

    Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

    Published: 4 Sept 2024
    6.2
    Medium

    CVE-2024-34637

    Last Modified: 5 Sept 2024

    Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.

    Published: 4 Sept 2024
    6.4
    Medium

    CVE-2024-8325

    Last Modified: 8 Apr 2026

    The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the ‘blockspare_render_social_sharing_block’ function in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Sept 2024