CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-23364

    Last Modified: 3 Oct 2025

    Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).

    Published: 2 Sept 2024
    7.1
    High

    CVE-2024-23362

    Last Modified: 3 Oct 2025

    Cryptographic issue while parsing RSA keys in COBR format.

    Published: 2 Sept 2024
    8.2
    High

    CVE-2024-23359

    Last Modified: 3 Oct 2025

    Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

    Published: 2 Sept 2024
    7.5
    High

    CVE-2024-23358

    Last Modified: 3 Oct 2025

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

    Published: 2 Sept 2024
    2.3
    Low

    CVE-2024-38858

    Last Modified: 4 Sept 2024

    Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

    Published: 2 Sept 2024
    —
    Unknown

    CVE-2024-8371

    Last Modified: 3 Sept 2024

    Duplicate of CVE-2024-45305.

    Published: 2 Sept 2024
    6.1
    Medium

    CVE-2024-7692

    Last Modified: 4 Oct 2024

    The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 2 Sept 2024
    6.1
    Medium

    CVE-2024-7691

    Last Modified: 4 Oct 2024

    The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.

    Published: 2 Sept 2024
    4.3
    Medium

    CVE-2024-7690

    Last Modified: 7 Oct 2024

    The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 2 Sept 2024
    6.1
    Medium

    CVE-2024-7354

    Last Modified: 4 Oct 2024

    The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 2 Sept 2024
    8.7
    High

    CVE-2024-43776

    Last Modified: 4 Sept 2024

    SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.

    Published: 2 Sept 2024
    8.7
    High

    CVE-2024-43775

    Last Modified: 4 Sept 2024

    SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.

    Published: 2 Sept 2024
    8.7
    High

    CVE-2024-43774

    Last Modified: 4 Sept 2024

    SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.

    Published: 2 Sept 2024
    9.3
    Critical

    CVE-2024-43773

    Last Modified: 4 Sept 2024

    SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.

    Published: 2 Sept 2024
    9.3
    Critical

    CVE-2024-43772

    Last Modified: 4 Sept 2024

    SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.

    Published: 2 Sept 2024
    8.7
    High

    CVE-2024-7871

    Last Modified: 23 Jan 2026

    SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.

    Published: 2 Sept 2024
    8.8
    High

    CVE-2024-41160

    Last Modified: 9 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

    Published: 2 Sept 2024
    8.8
    High

    CVE-2024-41157

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

    Published: 2 Sept 2024
    8.4
    High

    CVE-2024-39816

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

    Published: 2 Sept 2024
    6.5
    Medium

    CVE-2024-39775

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.

    Published: 2 Sept 2024
    5.5
    Medium

    CVE-2024-39612

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

    Published: 2 Sept 2024
    8.4
    High

    CVE-2024-38386

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

    Published: 2 Sept 2024
    5.5
    Medium

    CVE-2024-38382

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

    Published: 2 Sept 2024
    3.3
    Low

    CVE-2024-28044

    Last Modified: 4 Sept 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

    Published: 2 Sept 2024
    7.5
    High

    CVE-2024-20089

    Last Modified: 5 Sept 2024

    In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.

    Published: 2 Sept 2024
    4.4
    Medium

    CVE-2024-20088

    Last Modified: 13 Mar 2025

    In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932099; Issue ID: MSV-1543.

    Published: 2 Sept 2024
    6.7
    Medium

    CVE-2024-20087

    Last Modified: 5 Sept 2024

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.

    Published: 2 Sept 2024
    6.7
    Medium

    CVE-2024-20086

    Last Modified: 5 Sept 2024

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1551.

    Published: 2 Sept 2024
    4.4
    Medium

    CVE-2024-20085

    Last Modified: 27 Oct 2024

    In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.

    Published: 2 Sept 2024
    4.4
    Medium

    CVE-2024-20084

    Last Modified: 27 Oct 2024

    In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.

    Published: 2 Sept 2024
    6.2
    Medium

    CVE-2024-8365

    Last Modified: 4 Sept 2024

    Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being stored in the audit log. This vulnerability, CVE-2024-8365, was fixed in Vault Community Edition and Vault Enterprise 1.17.5 and Vault Enterprise 1.16.9.

    Published: 2 Sept 2024
    9.8
    Critical

    CVE-2024-45623

    Last Modified: 15 Apr 2026

    D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 2 Sept 2024
    5.5
    Medium

    CVE-2024-44947

    Last Modified: 3 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So fuse_notify_store() must be more careful to fully initialize page contents (including parts of the page that are beyond end-of-file) before marking the page uptodate. The current code can leave beyond-EOF page contents uninitialized, which makes these uninitialized page contents visible to userspace via mmap(). This is an information leak, but only affects systems which do not enable init-on-alloc (via CONFIG_INIT_ON_ALLOC_DEFAULT_ON=y or the corresponding kernel command line parameter).

    Published: 2 Sept 2024
    6.1
    Medium

    CVE-2024-45527

    Last Modified: 30 Apr 2025

    REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.

    Published: 2 Sept 2024
    5.4
    Medium

    CVE-2024-45528

    Last Modified: 31 Mar 2025

    CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

    Published: 2 Sept 2024
    4.3
    Medium

    CVE-2024-45619

    Last Modified: 30 Jun 2026

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

    Published: 2 Sept 2024
    5.4
    Medium

    CVE-2024-45621

    Last Modified: 13 Mar 2025

    The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents.

    Published: 2 Sept 2024
    3.9
    Low

    CVE-2024-45617

    Last Modified: 30 Jun 2026

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

    Published: 2 Sept 2024
    3.9
    Low

    CVE-2024-45618

    Last Modified: 30 Jun 2026

    A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.

    Published: 2 Sept 2024
    9.8
    Critical

    CVE-2024-45622

    Last Modified: 15 Apr 2026

    ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

    Published: 2 Sept 2024
    3.9
    Low

    CVE-2024-45615

    Last Modified: 30 Jun 2026

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

    Published: 2 Sept 2024
    3.9
    Low

    CVE-2024-45616

    Last Modified: 30 Jun 2026

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the card.

    Published: 2 Sept 2024
    3.9
    Low

    CVE-2024-45620

    Last Modified: 30 Jun 2026

    A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

    Published: 2 Sept 2024
    4.3
    Medium

    CVE-2024-45270

    Last Modified: 13 Mar 2025

    WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.

    Published: 1 Sept 2024
    4.3
    Medium

    CVE-2024-45269

    Last Modified: 13 Mar 2025

    WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.

    Published: 1 Sept 2024
    5.3
    Medium

    CVE-2024-8370

    Last Modified: 29 Sept 2025

    A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File Upload Handler. The manipulation of the argument force_serve_as with the input picture' leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. Unfortunately, the project maintainer does not want to be quoted in any way regarding the dispute rationale. The security policy of the project implies that this finding is "practically irrelevant" due to authentication requirements.

    Published: 1 Sept 2024
    4.2
    Medium

    CVE-2024-5053

    Last Modified: 8 Apr 2026

    The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. At the same time, missing Mailchimp API key validation allows the redirect of the integration requests to the attacker-controlled server.

    Published: 1 Sept 2024
    6.9
    Medium

    CVE-2024-8368

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Sept 2024
    5.1
    Medium

    CVE-2024-8367

    Last Modified: 15 Apr 2026

    A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a6cd31. It has been classified as problematic. Affected is an unknown function of the file src/main/java/uk/gov/hmcts/probate/service/NotificationService.java of the component Markdown Handler. The manipulation leads to injection. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as d90230d7cf575e5b0852d56660104c8bd2503c34. It is recommended to apply a patch to fix this issue.

    Published: 1 Sept 2024
    9.8
    Critical

    CVE-2024-45522

    Last Modified: 5 Sept 2024

    Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

    Published: 1 Sept 2024