CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-43861

    Last Modified: 3 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip packets Free the unused skb when not ip packets arrive.

    Published: 20 Aug 2024
    5.5
    Medium

    CVE-2024-43862

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlock to a mutex The carrier_lock spinlock protects the carrier detection. While it is held, framer_get_status() is called which in turn takes a mutex. This is not correct and can lead to a deadlock. A run with PROVE_LOCKING enabled detected the issue: [ BUG: Invalid wait context ] ... c204ddbc (&framer->mutex){+.+.}-{3:3}, at: framer_get_status+0x40/0x78 other info that might help us debug this: context-{4:4} 2 locks held by ifconfig/146: #0: c0926a38 (rtnl_mutex){+.+.}-{3:3}, at: devinet_ioctl+0x12c/0x664 #1: c2006a40 (&qmc_hdlc->carrier_lock){....}-{2:2}, at: qmc_hdlc_framer_set_carrier+0x30/0x98 Avoid the spinlock usage and convert carrier_lock to a mutex.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42919

    Last Modified: 12 Nov 2025

    eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

    Published: 20 Aug 2024
    8.1
    High

    CVE-2024-8007

    Last Modified: 25 Feb 2026

    A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.

    Published: 20 Aug 2024
    5.3
    Medium

    CVE-2024-7936

    Last Modified: 3 Sept 2024

    A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The manipulation of the argument start/end/employee leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    7.8
    High

    CVE-2024-7305

    Last Modified: 26 Aug 2025

    A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7935

    Last Modified: 23 Aug 2024

    A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file print.php. The manipulation of the argument map_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7934

    Last Modified: 23 Aug 2024

    A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file execute.php. The manipulation of the argument code leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7933

    Last Modified: 23 Aug 2024

    A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file login1.php of the component Backend Login. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    7.6
    High

    CVE-2024-4785

    Last Modified: 17 Sept 2025

    BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7931

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue affects some unknown processing of the file /tracking/admin/view_csprofile.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7930

    Last Modified: 23 Jan 2026

    A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/get_packings.php. The manipulation of the argument medicine_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7929

    Last Modified: 21 Aug 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7928

    Last Modified: 13 Sept 2024

    A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 19 Aug 2024
    —
    Unknown

    CVE-2024-7989

    Last Modified: 26 Aug 2024

    Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that the issue does not pose a security risk as it falls within the expected functionality and security controls of the application. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7927

    Last Modified: 4 Sept 2024

    A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7926

    Last Modified: 4 Sept 2024

    A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-43354

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-43345

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder: from n/a through 1.5.2.0.

    Published: 19 Aug 2024
    8.3
    High

    CVE-2024-43328

    Last Modified: 5 Apr 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.

    Published: 19 Aug 2024
    5.4
    Medium

    CVE-2024-43326

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7.

    Published: 19 Aug 2024
    4.3
    Medium

    CVE-2024-43317

    Last Modified: 4 Feb 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects RegistrationMagic: from n/a through 6.0.1.0.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-43311

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.

    Published: 19 Aug 2024
    —
    Unknown

    CVE-2024-7958

    Last Modified: 19 Aug 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7925

    Last Modified: 3 Sept 2024

    A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7924

    Last Modified: 21 Aug 2024

    A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of the file /I/list.php. The manipulation of the argument skin leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-43281

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.3.

    Published: 19 Aug 2024
    4.7
    Medium

    CVE-2024-43280

    Last Modified: 11 Apr 2025

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-43272

    Last Modified: 15 Apr 2026

    Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

    Published: 19 Aug 2024
    8.5
    High

    CVE-2024-43271

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allows PHP Local File Inclusion.This issue affects Woo Products Widgets For Elementor: from n/a through 2.0.0.

    Published: 19 Aug 2024
    9.6
    Critical

    CVE-2024-43261

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.

    Published: 19 Aug 2024
    7.1
    High

    CVE-2024-43256

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.

    Published: 19 Aug 2024
    9
    Critical

    CVE-2024-43252

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

    Published: 19 Aug 2024
    7.1
    High

    CVE-2024-43250

    Last Modified: 6 Sept 2024

    Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bit Form Pro: from n/a through 2.6.4.

    Published: 19 Aug 2024
    9.9
    Critical

    CVE-2024-43249

    Last Modified: 6 Sept 2024

    Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from n/a through 2.6.4.

    Published: 19 Aug 2024
    8.6
    High

    CVE-2024-43248

    Last Modified: 6 Sept 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.

    Published: 19 Aug 2024
    8.8
    High

    CVE-2024-43247

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-43245

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

    Published: 19 Aug 2024
    9
    Critical

    CVE-2024-43242

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

    Published: 19 Aug 2024
    9.4
    Critical

    CVE-2024-43240

    Last Modified: 23 Apr 2026

    Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

    Published: 19 Aug 2024
    4.7
    Medium

    CVE-2024-43236

    Last Modified: 15 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a through 1.9.

    Published: 19 Aug 2024
    8.5
    High

    CVE-2024-43232

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3.

    Published: 19 Aug 2024
    8.5
    High

    CVE-2024-43221

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclusion.This issue affects JetGridBuilder: from n/a through 1.1.2.

    Published: 19 Aug 2024
    10
    Critical

    CVE-2024-37099

    Last Modified: 28 Feb 2025

    Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.

    Published: 19 Aug 2024
    7.8
    High

    CVE-2024-32927

    Last Modified: 20 Aug 2024

    In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Aug 2024
    5.9
    Medium

    CVE-2024-32928

    Last Modified: 14 Mar 2025

    The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.

    Published: 19 Aug 2024
    9
    Critical

    CVE-2024-43400

    Last Modified: 22 Aug 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to follow the URL. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

    Published: 19 Aug 2024
    9
    Critical

    CVE-2024-43401

    Last Modified: 21 Aug 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-6348

    Last Modified: 20 Aug 2024

    Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7922

    Last Modified: 20 Aug 2024

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

    Published: 19 Aug 2024