CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2024-5490

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

    Published: 23 Aug 2024
    8.3
    High

    CVE-2024-36514

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

    Published: 23 Aug 2024
    8.3
    High

    CVE-2024-36515

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.

    Published: 23 Aug 2024
    8.3
    High

    CVE-2024-36516

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.

    Published: 23 Aug 2024
    8.3
    High

    CVE-2024-36517

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

    Published: 23 Aug 2024
    8.3
    High

    CVE-2024-5467

    Last Modified: 27 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-5466

    Last Modified: 19 Dec 2024

    Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

    Published: 23 Aug 2024
    6.8
    Medium

    CVE-2024-7986

    Last Modified: 28 Aug 2024

    A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

    Published: 23 Aug 2024
    6.4
    Medium

    CVE-2024-5502

    Last Modified: 8 Apr 2026

    The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Aug 2024
    6.3
    Medium

    CVE-2024-38807

    Last Modified: 15 Apr 2026

    Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where content that appears to have been signed by one signer has, in fact, been signed by another.

    Published: 23 Aug 2024
    4.3
    Medium

    CVE-2024-43105

    Last Modified: 17 Mar 2026

    Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-40766

    Last Modified: 31 Oct 2025

    An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

    Published: 23 Aug 2024
    6.1
    Medium

    CVE-2024-6715

    Last Modified: 17 May 2025

    The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerability/80a9eb3a-2cb1-4844-9004-ba2554b2d46c/) in v3.1.39

    Published: 23 Aug 2024
    4.8
    Medium

    CVE-2024-3282

    Last Modified: 17 May 2025

    The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-7258

    Last Modified: 8 Apr 2026

    The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and including, 2.8.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-7559

    Last Modified: 8 Apr 2026

    The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 23 Aug 2024
    7.5
    High

    CVE-2024-43477

    Last Modified: 10 Jul 2025

    Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-43883

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-22273, though there may be similar races in the driver.

    Published: 23 Aug 2024
    9.1
    Critical

    CVE-2024-42914

    Last Modified: 21 Apr 2025

    A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.

    Published: 23 Aug 2024
    4.3
    Medium

    CVE-2024-43032

    Last Modified: 3 Sept 2025

    autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-44382

    Last Modified: 26 Aug 2024

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

    Published: 23 Aug 2024
    7.3
    High

    CVE-2024-44386

    Last Modified: 4 Apr 2025

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

    Published: 23 Aug 2024
    9.1
    Critical

    CVE-2024-33852

    Last Modified: 9 May 2025

    A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

    Published: 23 Aug 2024
    9.1
    Critical

    CVE-2024-33853

    Last Modified: 9 May 2025

    A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

    Published: 23 Aug 2024
    9.1
    Critical

    CVE-2024-33854

    Last Modified: 9 May 2025

    A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

    Published: 23 Aug 2024
    6.1
    Medium

    CVE-2024-37392

    Last Modified: 20 Mar 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which gets executed when the SMS is viewed and specially interacted in web-GUI.

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-42756

    Last Modified: 30 Jan 2026

    An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-39841

    Last Modified: 9 May 2025

    A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

    Published: 23 Aug 2024
    4.8
    Medium

    CVE-2024-40111

    Last Modified: 21 Apr 2025

    A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.

    Published: 23 Aug 2024
    7.2
    High

    CVE-2024-42523

    Last Modified: 21 Apr 2025

    publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

    Published: 23 Aug 2024
    7.2
    High

    CVE-2024-42636

    Last Modified: 31 Mar 2025

    DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

    Published: 23 Aug 2024
    9.4
    Critical

    CVE-2024-42764

    Last Modified: 6 May 2025

    Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-42765

    Last Modified: 6 May 2025

    A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.

    Published: 23 Aug 2024
    5.4
    Medium

    CVE-2024-42766

    Last Modified: 26 Aug 2024

    Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

    Published: 23 Aug 2024
    8
    High

    CVE-2024-42845

    Last Modified: 15 Apr 2026

    An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

    Published: 23 Aug 2024
    5.4
    Medium

    CVE-2024-42918

    Last Modified: 13 Mar 2025

    itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.

    Published: 23 Aug 2024
    —
    Unknown

    CVE-2024-42992

    Last Modified: 26 Aug 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Aug 2024
    4.3
    Medium

    CVE-2024-43031

    Last Modified: 3 Sept 2025

    autMan v2.9.6 was discovered to contain an access control issue.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-44381

    Last Modified: 26 Aug 2024

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

    Published: 23 Aug 2024
    6.5
    Medium

    CVE-2024-44387

    Last Modified: 13 Dec 2024

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

    Published: 23 Aug 2024
    8.8
    High

    CVE-2024-44390

    Last Modified: 13 Dec 2024

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.

    Published: 23 Aug 2024
    8.1
    High

    CVE-2024-42040

    Last Modified: 3 Apr 2026

    Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-32501

    Last Modified: 9 May 2025

    A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

    Published: 23 Aug 2024
    9.8
    Critical

    CVE-2024-42531

    Last Modified: 15 Apr 2026

    Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.

    Published: 23 Aug 2024
    6.1
    Medium

    CVE-2024-42852

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.

    Published: 23 Aug 2024
    8
    High

    CVE-2024-42915

    Last Modified: 15 Apr 2026

    A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.

    Published: 23 Aug 2024
    5.3
    Medium

    CVE-2024-8089

    Last Modified: 27 Aug 2024

    A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Aug 2024
    7.8
    High

    CVE-2024-38210

    Last Modified: 10 Jul 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 22 Aug 2024
    6.1
    Medium

    CVE-2024-38208

    Last Modified: 10 Jul 2025

    Microsoft Edge for Android Spoofing Vulnerability

    Published: 22 Aug 2024
    7.8
    High

    CVE-2024-38209

    Last Modified: 10 Jul 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 22 Aug 2024