CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-7628

    Last Modified: 8 Apr 2026

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.15.2. This is due to the use of loose comparison in the 'verify_id_token' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to an @flutter.io email address or phone number. This also requires firebase to be configured on the website and the user to have set up firebase for their account.

    Published: 15 Aug 2024
    8.1
    High

    CVE-2024-7624

    Last Modified: 8 Apr 2026

    The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.

    Published: 15 Aug 2024
    5.8
    Medium

    CVE-2024-7420

    Last Modified: 8 Apr 2026

    The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unauthenticated attackers to activate/deactivate and delete code snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2024-43275 appears to be a duplicate of this issue.

    Published: 15 Aug 2024
    5.3
    Medium

    CVE-2024-7810

    Last Modified: 11 Jul 2025

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/view_itprofile.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Aug 2024
    6.9
    Medium

    CVE-2024-7809

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Aug 2024
    6.9
    Medium

    CVE-2024-7808

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file logindbc.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Aug 2024
    6.1
    Medium

    CVE-2024-42678

    Last Modified: 18 Nov 2024

    Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42942

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42949

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42955

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42973

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42980

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42987

    Last Modified: 2 Sept 2025

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd function. The vulnerability can be triggered via the modino, username, newpwd, or pptpdnetseg parameters, all of which are passed via HTTP POST and used in unsafe sprintf calls without proper length validation. A remote attacker can exploit this flaw through a crafted POST request, which may cause a Denial of Service (DoS). In certain scenarios, this issue could potentially be leveraged to achieve remote code execution.

    Published: 15 Aug 2024
    6.8
    Medium

    CVE-2024-31800

    Last Modified: 30 Oct 2024

    Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.

    Published: 15 Aug 2024
    6.1
    Medium

    CVE-2024-27728

    Last Modified: 4 Jun 2025

    Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.

    Published: 15 Aug 2024
    8.8
    High

    CVE-2024-22218

    Last Modified: 15 Apr 2026

    XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-23168

    Last Modified: 15 Apr 2026

    Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

    Published: 15 Aug 2024
    6.1
    Medium

    CVE-2024-27729

    Last Modified: 11 Sept 2024

    Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-27730

    Last Modified: 4 Jun 2025

    Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.

    Published: 15 Aug 2024
    6.1
    Medium

    CVE-2024-27731

    Last Modified: 4 Jun 2025

    Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter.

    Published: 15 Aug 2024
    6.8
    Medium

    CVE-2024-31798

    Last Modified: 16 Aug 2024

    Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices

    Published: 15 Aug 2024
    4.6
    Medium

    CVE-2024-31799

    Last Modified: 16 Aug 2024

    Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

    Published: 15 Aug 2024
    6.3
    Medium

    CVE-2024-32231

    Last Modified: 10 Jul 2025

    Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-23185

    Last Modified: 15 Apr 2026

    Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It doesn't matter whether it's a single long header line, or a single header split into multiple lines. This bug exists in all Dovecot versions. Incoming mails typically have some size limits set by MTA, so even largest possible header size may still fit into Dovecot's vsz_limit. So attackers probably can't DoS a victim user this way. A user could APPEND larger mails though, allowing them to DoS themselves (although maybe cause some memory issues for the backend in general). One can implement restrictions on headers on MTA component preceding Dovecot. No publicly available exploits are known.

    Published: 15 Aug 2024
    8.8
    High

    CVE-2024-42676

    Last Modified: 18 Nov 2024

    File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component

    Published: 15 Aug 2024
    5.5
    Medium

    CVE-2024-42677

    Last Modified: 18 Nov 2024

    An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component

    Published: 15 Aug 2024
    7.8
    High

    CVE-2024-42679

    Last Modified: 6 Sept 2024

    SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.

    Published: 15 Aug 2024
    5.5
    Medium

    CVE-2024-42680

    Last Modified: 25 Mar 2025

    An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark.

    Published: 15 Aug 2024
    8.8
    High

    CVE-2024-42681

    Last Modified: 19 Aug 2024

    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-42843

    Last Modified: 19 Aug 2024

    Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42941

    Last Modified: 3 Sept 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42940

    Last Modified: 3 Sept 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42943

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42944

    Last Modified: 15 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42945

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42946

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-42947

    Last Modified: 13 Mar 2025

    An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42948

    Last Modified: 3 Sept 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42950

    Last Modified: 21 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42951

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42952

    Last Modified: 18 Mar 2025

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42953

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42954

    Last Modified: 16 Aug 2024

    Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-42966

    Last Modified: 24 Oct 2024

    Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-42967

    Last Modified: 13 Mar 2025

    Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42968

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42969

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42974

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42976

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42977

    Last Modified: 24 Oct 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024