CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-42978

    Last Modified: 25 Mar 2025

    An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42979

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42981

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42982

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42983

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42984

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42985

    Last Modified: 16 Aug 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    7.5
    High

    CVE-2024-42986

    Last Modified: 24 Oct 2024

    Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 15 Aug 2024
    6.5
    Medium

    CVE-2024-22217

    Last Modified: 24 Mar 2025

    A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.

    Published: 15 Aug 2024
    9.8
    Critical

    CVE-2024-42757

    Last Modified: 15 Apr 2026

    Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

    Published: 15 Aug 2024
    6.3
    Medium

    CVE-2024-22219

    Last Modified: 15 Apr 2026

    XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.

    Published: 15 Aug 2024
    5
    Medium

    CVE-2024-23184

    Last Modified: 15 Apr 2026

    Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known.

    Published: 15 Aug 2024
    5.3
    Medium

    CVE-2024-7800

    Last Modified: 19 Aug 2024

    A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=delete_product. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    6.9
    Medium

    CVE-2024-7799

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/bidding/admin/users.php. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    5.8
    Medium

    CVE-2024-7625

    Last Modified: 29 Dec 2025

    In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

    Published: 14 Aug 2024
    6.9
    Medium

    CVE-2024-7798

    Last Modified: 3 Sept 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login2. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    6.9
    Medium

    CVE-2024-7797

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-43368

    Last Modified: 15 Apr 2026

    The Trix editor, versions prior to 2.1.4, is vulnerable to XSS when pasting malicious code. This vulnerability is a bypass of the fix put in place for GHSA-qjqp-xr96-cj99. In pull request 1149, sanitation was added for Trix attachments with a `text/html` content type. However, Trix only checks the content type on the paste event's `dataTransfer` object. As long as the `dataTransfer` has a content type of `text/html`, Trix parses its contents and creates an `Attachment` with them, even if the attachment itself doesn't have a `text/html` content type. Trix then uses the attachment content to set the attachment element's `innerHTML`. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. This vulnerability was fixed in version 2.1.4.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-7794

    Last Modified: 19 Dec 2025

    A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file mybill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-7793

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-40620

    Last Modified: 31 Jan 2025

    CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.

    Published: 14 Aug 2024
    7.7
    High

    CVE-2024-27120

    Last Modified: 11 Mar 2025

    A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.

    Published: 14 Aug 2024
    8.7
    High

    CVE-2024-40619

    Last Modified: 31 Jan 2025

    CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.

    Published: 14 Aug 2024
    9.8
    Critical

    CVE-2024-42360

    Last Modified: 16 Aug 2024

    SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This vulnerability has been fixed in 3.1.2.

    Published: 14 Aug 2024
    8.5
    High

    CVE-2024-7513

    Last Modified: 15 Aug 2025

    CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.

    Published: 14 Aug 2024
    —
    Unknown

    CVE-2024-7821

    Last Modified: 4 Sept 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Aug 2024
    8.6
    High

    CVE-2024-6078

    Last Modified: 15 Apr 2026

    CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.

    Published: 14 Aug 2024
    8.7
    High

    CVE-2024-7515

    Last Modified: 15 Aug 2024

    CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.

    Published: 14 Aug 2024
    8.7
    High

    CVE-2024-7507

    Last Modified: 15 Aug 2024

    CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-7792

    Last Modified: 20 Aug 2024

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. The manipulation of the argument task leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-31882

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287614.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-37529

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 294295.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-35152

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-35136

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2023-50314

    Last Modified: 23 Aug 2024

    IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2023-50315

    Last Modified: 11 Sept 2024

    IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.

    Published: 14 Aug 2024
    —
    Unknown

    CVE-2024-7805

    Last Modified: 11 Sept 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Aug 2024
    6.2
    Medium

    CVE-2024-42441

    Last Modified: 7 Oct 2025

    Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

    Published: 14 Aug 2024
    6.2
    Medium

    CVE-2024-42440

    Last Modified: 28 Aug 2024

    Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-42439

    Last Modified: 29 Aug 2024

    Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-42438

    Last Modified: 29 Aug 2024

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 Aug 2024
    6
    Medium

    CVE-2024-5916

    Last Modified: 30 Apr 2025

    An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-42437

    Last Modified: 4 Sept 2024

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 Aug 2024
    6.5
    Medium

    CVE-2024-42436

    Last Modified: 4 Sept 2024

    Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 Aug 2024
    5.2
    Medium

    CVE-2024-5915

    Last Modified: 20 Aug 2024

    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.

    Published: 14 Aug 2024
    7
    High

    CVE-2024-5914

    Last Modified: 20 Aug 2024

    A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

    Published: 14 Aug 2024
    4.9
    Medium

    CVE-2024-42435

    Last Modified: 4 Sept 2024

    Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

    Published: 14 Aug 2024
    4.9
    Medium

    CVE-2024-42434

    Last Modified: 7 Oct 2025

    Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

    Published: 14 Aug 2024
    4.9
    Medium

    CVE-2024-39824

    Last Modified: 2 Oct 2025

    Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

    Published: 14 Aug 2024
    4.9
    Medium

    CVE-2024-39823

    Last Modified: 2 Oct 2025

    Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

    Published: 14 Aug 2024