CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-43399

    Last Modified: 20 Aug 2024

    Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension files, the measure intended to prevent Zip Slip attacks is improperly implemented. Since the implemented measure can be bypassed, the vulnerability allows an attacker to extract files to any desired location within the server running MobSF. This vulnerability is fixed in 4.0.7.

    Published: 19 Aug 2024
    3.4
    Low

    CVE-2024-43379

    Last Modified: 21 Aug 2024

    TruffleHog is a secrets scanning tool. Prior to v3.81.9, this vulnerability allows a malicious actor to craft data in a way that, when scanned by specific detectors, could trigger the detector to make an unauthorized request to an endpoint chosen by the attacker. For an exploit to be effective, the target endpoint must be an unauthenticated GET endpoint that produces side effects. The victim must scan the maliciously crafted data and have such an endpoint targeted for the exploit to succeed. The vulnerability has been resolved in TruffleHog v3.81.9 and later versions.

    Published: 19 Aug 2024
    5.4
    Medium

    CVE-2024-25582

    Last Modified: 15 Apr 2026

    Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform malicious API requests or extract information from the users account. Exploiting this vulnerability requires temporary access to an account or successful social engineering to make a user follow a prepared link to a malicious account. Please deploy the provided updates and patch releases. The savepoint module path has been restricted to modules that provide the feature, excluding any arbitrary or non-existing modules. No publicly available exploits are known.

    Published: 19 Aug 2024
    6.1
    Medium

    CVE-2024-6843

    Last Modified: 27 May 2025

    The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins

    Published: 19 Aug 2024
    7.2
    High

    CVE-2024-6451

    Last Modified: 27 May 2025

    AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-6330

    Last Modified: 27 May 2025

    The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-43440

    Last Modified: 1 May 2025

    A flaw was found in moodle. A local file may include risks when restoring block backups.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7921

    Last Modified: 21 Aug 2024

    A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /report/ParkOutRecord/GetDataList. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-7920

    Last Modified: 21 Aug 2024

    A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Affected is an unknown function of the file /Report/ParkCommon/GetParkInThroughDeivces. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    6.9
    Medium

    CVE-2024-7919

    Last Modified: 21 Aug 2024

    A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. This issue affects some unknown processing of the file /report/ParkChargeRecord/GetDataList. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 19 Aug 2024
    8
    High

    CVE-2024-6508

    Last Modified: 11 Aug 2026

    An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-42813

    Last Modified: 1 Apr 2025

    In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-43380

    Last Modified: 3 Sept 2024

    fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.

    Published: 19 Aug 2024
    8.4
    High

    CVE-2024-44067

    Last Modified: 15 Apr 2026

    The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.

    Published: 19 Aug 2024
    6.5
    Medium

    CVE-2024-35539

    Last Modified: 1 May 2025

    Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

    Published: 19 Aug 2024
    6.1
    Medium

    CVE-2024-23729

    Last Modified: 20 Aug 2024

    The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.

    Published: 19 Aug 2024
    5.3
    Medium

    CVE-2024-35538

    Last Modified: 28 Apr 2025

    Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

    Published: 19 Aug 2024
    8.8
    High

    CVE-2024-42633

    Last Modified: 20 Aug 2024

    A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-42657

    Last Modified: 20 Aug 2024

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-42658

    Last Modified: 20 Aug 2024

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-42812

    Last Modified: 17 Mar 2025

    In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-42815

    Last Modified: 9 Jul 2025

    In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-44073

    Last Modified: 13 Sept 2024

    The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth.

    Published: 19 Aug 2024
    9.8
    Critical

    CVE-2024-44076

    Last Modified: 21 Aug 2024

    In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-44069

    Last Modified: 10 Oct 2025

    Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-44083

    Last Modified: 18 Mar 2025

    ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

    Published: 19 Aug 2024
    7.5
    High

    CVE-2024-7592

    Last Modified: 3 Nov 2025

    There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

    Published: 19 Aug 2024
    5.1
    Medium

    CVE-2024-7917

    Last Modified: 21 Aug 2024

    A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument site_favicon leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2024
    5.3
    Medium

    CVE-2024-7916

    Last Modified: 22 Apr 2025

    A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addNominee.php of the component Add Nominee Page. The manipulation of the argument Nominee-Client ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2024
    5.3
    Medium

    CVE-2024-7914

    Last Modified: 19 Aug 2024

    A vulnerability classified as problematic has been found in SourceCodester Yoga Class Registration System 1.0. Affected is an unknown function of the file /php-ycrs/classes/SystemSettings.php. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2024
    6.9
    Medium

    CVE-2024-7913

    Last Modified: 19 Aug 2024

    A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2024
    5.3
    Medium

    CVE-2024-35686

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects Sensei LMS: from n/a through 4.23.1; Sensei Pro (WC Paid Courses): from n/a through 4.23.1.1.23.1.

    Published: 18 Aug 2024
    8.5
    High

    CVE-2024-43145

    Last Modified: 13 Mar 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61.

    Published: 18 Aug 2024
    8.5
    High

    CVE-2024-43207

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Valiano Unite Gallery Lite.This issue affects Unite Gallery Lite: from n/a through 1.7.62.

    Published: 18 Aug 2024
    7.6
    High

    CVE-2024-43282

    Last Modified: 22 Jan 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

    Published: 18 Aug 2024
    8.5
    High

    CVE-2024-43286

    Last Modified: 31 Mar 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.3.19.

    Published: 18 Aug 2024
    4.3
    Medium

    CVE-2024-43239

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.

    Published: 18 Aug 2024
    5.4
    Medium

    CVE-2024-43266

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.8.

    Published: 18 Aug 2024
    4.3
    Medium

    CVE-2024-43288

    Last Modified: 6 Feb 2025

    Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.

    Published: 18 Aug 2024
    7.5
    High

    CVE-2024-43315

    Last Modified: 15 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.

    Published: 18 Aug 2024
    5.4
    Medium

    CVE-2024-43322

    Last Modified: 11 Feb 2025

    Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.

    Published: 18 Aug 2024
    6.9
    Medium

    CVE-2024-7912

    Last Modified: 19 Aug 2024

    A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/assets/. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2024
    5.3
    Medium

    CVE-2024-43350

    Last Modified: 15 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.

    Published: 18 Aug 2024
    7.1
    High

    CVE-2024-43241

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.

    Published: 18 Aug 2024
    7.1
    High

    CVE-2024-43244

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS.This issue affects Houzez: from n/a through 3.2.4.

    Published: 18 Aug 2024
    7.1
    High

    CVE-2024-43246

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5.

    Published: 18 Aug 2024
    6.5
    Medium

    CVE-2024-43262

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webriti Busiprof allows Stored XSS.This issue affects Busiprof: from n/a through 2.4.8.

    Published: 18 Aug 2024
    6.5
    Medium

    CVE-2024-43263

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visual Composer Visual Composer Starter allows Stored XSS.This issue affects Visual Composer Starter: from n/a through 3.3.

    Published: 18 Aug 2024
    6.5
    Medium

    CVE-2024-43267

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Qamar Sheeraz, Nasir Ahmad, GenialSouls Mega Addons For Elementor allows Stored XSS.This issue affects Mega Addons For Elementor: from n/a through 1.9.

    Published: 18 Aug 2024
    6.5
    Medium

    CVE-2024-43278

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

    Published: 18 Aug 2024