CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-48888

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Fix memory leak in msm_mdss_parse_data_bus_icc_path of_icc_get() alloc resources for path1, we should release it when not need anymore. Early return when IS_ERR_OR_NULL(path0) may leak path1. Defer getting path1 to fix this. Patchwork: https://patchwork.freedesktop.org/patch/514264/

    Published: 21 Aug 2024
    5.5
    Medium

    CVE-2023-52893

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so we must allow for that in gsmi. commit 859748255b43 ("efi: pstore: Omit efivars caching EFI varstore access layer") added a new get_variable call with attr=NULL, which triggers panic in gsmi.

    Published: 21 Aug 2024
    4.7
    Medium

    CVE-2023-52898

    Last Modified: 21 May 2025

    In the Linux kernel, the following vulnerability has been resolved: xhci: Fix null pointer dereference when host dies Make sure xhci_free_dev() and xhci_kill_endpoint_urbs() do not race and cause null pointer dereference when host suddenly dies. Usb core may call xhci_free_dev() which frees the xhci->devs[slot_id] virt device at the same time that xhci_kill_endpoint_urbs() tries to loop through all the device's endpoints, checking if there are any cancelled urbs left to give back. hold the xhci spinlock while freeing the virt device

    Published: 21 Aug 2024
    5.5
    Medium

    CVE-2023-52901

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check endpoint is valid before dereferencing it When the host controller is not responding, all URBs queued to all endpoints need to be killed. This can cause a kernel panic if we dereference an invalid endpoint. Fix this by using xhci_get_virt_ep() helper to find the endpoint and checking if the endpoint is valid before dereferencing it. [233311.853271] xhci-hcd xhci-hcd.1.auto: xHCI host controller not responding, assume dead [233311.853393] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000e8 [233311.853964] pc : xhci_hc_died+0x10c/0x270 [233311.853971] lr : xhci_hc_died+0x1ac/0x270 [233311.854077] Call trace: [233311.854085] xhci_hc_died+0x10c/0x270 [233311.854093] xhci_stop_endpoint_command_watchdog+0x100/0x1a4 [233311.854105] call_timer_fn+0x50/0x2d4 [233311.854112] expire_timers+0xac/0x2e4 [233311.854118] run_timer_softirq+0x300/0xabc [233311.854127] __do_softirq+0x148/0x528 [233311.854135] irq_exit+0x194/0x1a8 [233311.854143] __handle_domain_irq+0x164/0x1d0 [233311.854149] gic_handle_irq.22273+0x10c/0x188 [233311.854156] el1_irq+0xfc/0x1a8 [233311.854175] lpm_cpuidle_enter+0x25c/0x418 [msm_pm] [233311.854185] cpuidle_enter_state+0x1f0/0x764 [233311.854194] do_idle+0x594/0x6ac [233311.854201] cpu_startup_entry+0x7c/0x80 [233311.854209] secondary_start_kernel+0x170/0x198

    Published: 21 Aug 2024
    5.5
    Medium

    CVE-2023-52905

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix resource leakage in VF driver unbind resources allocated like mcam entries to support the Ntuple feature and hash tables for the tc feature are not getting freed in driver unbind. This patch fixes the issue.

    Published: 21 Aug 2024
    5.3
    Medium

    CVE-2024-8023

    Last Modified: 4 Jun 2025

    A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Aug 2024
    5.3
    Medium

    CVE-2024-8022

    Last Modified: 15 Apr 2026

    A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This issue affects some unknown processing of the file /vood/cgi-bin/vood_view.cgi?lang=EN&act=user/spec_conf&sessionId=86213915328111654515&user=A&message2user=Account%20updated. The manipulation of the argument Phone Number leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-22281

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-43403

    Last Modified: 15 Apr 2026

    Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. The "edit" ClusterRole is one of Kubernetes default-created ClusterRole, and it has the create/patch/udpate verbs of daemonset resources, create verb of serviceaccount/token resources, and impersonate verb of serviceaccounts resources. A malicious user can leverage access the worker node which has this component to make a cluster-level privilege escalation.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42362

    Last Modified: 28 Aug 2024

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-42361

    Last Modified: 3 Sept 2024

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection.

    Published: 20 Aug 2024
    5.4
    Medium

    CVE-2024-43396

    Last Modified: 3 Sept 2024

    Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for the /api/automation endpoint does not get correctly sanitized when rendered on the page, resulting in the ability of users to inject arbitrary HTML/JS. This vulnerability is fixed in 1.15.0.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42363

    Last Modified: 15 Apr 2026

    Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the YAML.load_stream method. This issue may lead to Remote Code Execution (RCE). This vulnerability is fixed in 3385.

    Published: 20 Aug 2024
    6.1
    Medium

    CVE-2024-41658

    Last Modified: 28 Aug 2024

    Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS. When purchasing an item through casdoor, the product page allows you to pay via wechat pay. When using wechat pay, a QR code with the wechat pay link is displayed on the payment page, hosted on the domain of casdoor. This page takes a query parameter from the url successUrl, and redirects the user to that url after a successful purchase. Because the user has no reason to think that the payment page contains sensitive information, they may share it with other or can be social engineered into sending it to others. An attacker can then craft the casdoor link with a special url and send it back to the user, and once payment has gone though an XSS attack occurs.

    Published: 20 Aug 2024
    8.1
    High

    CVE-2024-41657

    Last Modified: 28 Aug 2024

    Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

    Published: 20 Aug 2024
    8.1
    High

    CVE-2024-41659

    Last Modified: 10 Jul 2025

    memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.

    Published: 20 Aug 2024
    6.5
    Medium

    CVE-2024-41773

    Last Modified: 26 Aug 2024

    IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.

    Published: 20 Aug 2024
    9.5
    Critical

    CVE-2024-6800

    Last Modified: 30 Sept 2024

    An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML response to provision and/or gain access to a user with site administrator privileges. Exploitation of this vulnerability would allow unauthorized access to the instance without requiring prior authentication. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14, and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 20 Aug 2024
    5.9
    Medium

    CVE-2024-6337

    Last Modified: 27 Sept 2024

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and installation access token was not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.13.3, 3.12.8, 3.11.14 and 3.10.16. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 20 Aug 2024
    5.3
    Medium

    CVE-2024-7711

    Last Modified: 27 Sept 2024

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14 and was fixed in versions 3.13.3, 3.12.8, and 3.11.14. Versions 3.10 of GitHub Enterprise Server are not affected. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 20 Aug 2024
    9.6
    Critical

    CVE-2024-38175

    Last Modified: 10 Jul 2025

    An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

    Published: 20 Aug 2024
    5.4
    Medium

    CVE-2024-6322

    Last Modified: 15 Apr 2026

    Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

    Published: 20 Aug 2024
    7.1
    High

    CVE-2024-35214

    Last Modified: 15 Apr 2026

    A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.

    Published: 20 Aug 2024
    6.3
    Medium

    CVE-2024-43408

    Last Modified: 15 Apr 2026

    Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is fixed in commit a62f711d5600e4e5d86f342d52932cb6221672e7.

    Published: 20 Aug 2024
    9.1
    Critical

    CVE-2024-27185

    Last Modified: 4 Jun 2025

    The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

    Published: 20 Aug 2024
    6.1
    Medium

    CVE-2024-27186

    Last Modified: 4 Jun 2025

    The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

    Published: 20 Aug 2024
    6.1
    Medium

    CVE-2024-27184

    Last Modified: 4 Jun 2025

    Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

    Published: 20 Aug 2024
    6.1
    Medium

    CVE-2024-40743

    Last Modified: 4 Jun 2025

    The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-27187

    Last Modified: 4 Jun 2025

    Improper Access Controls allows backend users to overwrite their username when disallowed.

    Published: 20 Aug 2024
    6.5
    Medium

    CVE-2024-43409

    Last Modified: 3 Sept 2024

    Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-43406

    Last Modified: 26 Aug 2024

    LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-43404

    Last Modified: 26 Aug 2024

    MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when using `/math` in any Discord channel. This vulnerability impacts any discord guild utilizing MEGABOT. This vulnerability was fixed in release version 1.5.0.

    Published: 20 Aug 2024
    4.3
    Medium

    CVE-2024-43397

    Last Modified: 26 Aug 2024

    Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.

    Published: 20 Aug 2024
    5.4
    Medium

    CVE-2024-43377

    Last Modified: 3 Sept 2024

    Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.

    Published: 20 Aug 2024
    4.3
    Medium

    CVE-2024-43376

    Last Modified: 26 Aug 2024

    Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.

    Published: 20 Aug 2024
    4.1
    Medium

    CVE-2024-42369

    Last Modified: 3 Sept 2024

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This method is public but also called by the 'leaveRoomChain()' method, so leaving a room will also trigger the bug. This was patched in matrix-js-sdk 34.3.1.

    Published: 20 Aug 2024
    8.4
    High

    CVE-2024-39690

    Last Modified: 14 Aug 2025

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace. Version 0.7.1 contains a patch.

    Published: 20 Aug 2024
    6.9
    Medium

    CVE-2024-8005

    Last Modified: 21 Aug 2024

    A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.2 is able to address this issue. The patch is named be702ada7cb6fdabc02689d90b38139c827458a5. It is recommended to upgrade the affected component.

    Published: 20 Aug 2024
    8.1
    High

    CVE-2024-6377

    Last Modified: 27 Aug 2024

    An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.

    Published: 20 Aug 2024
    8.7
    High

    CVE-2024-6378

    Last Modified: 21 Aug 2024

    A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 20 Aug 2024
    7.7
    High

    CVE-2024-6379

    Last Modified: 27 Aug 2024

    A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 20 Aug 2024
    5.1
    Medium

    CVE-2024-8003

    Last Modified: 21 Aug 2024

    A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as 45ac90d6d1f82716f77dbcdf8e7309c229080e3c. It is recommended to apply a patch to fix this issue.

    Published: 20 Aug 2024
    8.2
    High

    CVE-2024-42336

    Last Modified: 27 Aug 2024

    Servision - CWE-287: Improper Authentication

    Published: 20 Aug 2024
    5.4
    Medium

    CVE-2024-42335

    Last Modified: 21 Aug 2024

    7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 20 Aug 2024
    —
    Unknown

    CVE-2024-42334

    Last Modified: 8 Sept 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-6918

    Last Modified: 15 Apr 2026

    CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-41700

    Last Modified: 3 Sept 2024

    Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

    Published: 20 Aug 2024
    6.5
    Medium

    CVE-2024-25009

    Last Modified: 15 Apr 2026

    Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where improper input validation can lead to denial of service which may result in service degradation.

    Published: 20 Aug 2024
    4.4
    Medium

    CVE-2024-41699

    Last Modified: 3 Sept 2024

    Priority – CWE-552: Files or Directories Accessible to External Parties

    Published: 20 Aug 2024
    4.3
    Medium

    CVE-2024-41698

    Last Modified: 3 Sept 2024

    Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    Published: 20 Aug 2024