CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-7732

    Last Modified: 3 Oct 2024

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

    Published: 14 Aug 2024
    9.8
    Critical

    CVE-2024-7731

    Last Modified: 22 Aug 2024

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

    Published: 14 Aug 2024
    6.4
    Medium

    CVE-2024-7588

    Last Modified: 15 Apr 2026

    The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Aug 2024
    7.5
    High

    CVE-2024-7729

    Last Modified: 15 Apr 2026

    The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.

    Published: 14 Aug 2024
    7.2
    High

    CVE-2024-7728

    Last Modified: 15 Apr 2026

    The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

    Published: 14 Aug 2024
    9.8
    Critical

    CVE-2024-20083

    Last Modified: 30 May 2025

    In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.

    Published: 14 Aug 2024
    9.8
    Critical

    CVE-2024-20082

    Last Modified: 30 May 2025

    In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529.

    Published: 14 Aug 2024
    9.1
    Critical

    CVE-2024-38652

    Last Modified: 15 Aug 2024

    Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

    Published: 14 Aug 2024
    7.2
    High

    CVE-2024-37373

    Last Modified: 16 Aug 2024

    Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

    Published: 14 Aug 2024
    7.5
    High

    CVE-2024-37399

    Last Modified: 15 Aug 2024

    A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

    Published: 14 Aug 2024
    7.5
    High

    CVE-2024-38653

    Last Modified: 15 Aug 2024

    XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

    Published: 14 Aug 2024
    7.5
    High

    CVE-2024-36136

    Last Modified: 15 Aug 2024

    An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-7754

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ajax/check_medicine_name.php. The manipulation of the argument user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    6.9
    Medium

    CVE-2024-7753

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user_images/. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2024
    7.8
    High

    CVE-2024-42259

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix Virtual Memory mapping boundaries calculation Calculating the size of the mapped area as the lesser value between the requested size and the actual size does not consider the partial mapping offset. This can cause page fault access. Fix the calculation of the starting and ending addresses, the total size is now deduced from the difference between the end and start addresses. Additionally, the calculations have been rewritten in a clearer and more understandable form. [Joonas: Add Requires: tag] Requires: 60a2066c5005 ("drm/i915/gem: Adjust vma offset for framebuffer mmap offset") (cherry picked from commit 97b6784753da06d9d40232328efc5c5367e53417)

    Published: 14 Aug 2024
    5.9
    Medium

    CVE-2024-27267

    Last Modified: 29 Sept 2025

    The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and 8.0.0.0 through 8.0.8.26 is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.

    Published: 14 Aug 2024
    6.1
    Medium

    CVE-2024-42353

    Last Modified: 19 Aug 2024

    WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's urlparse, and joining it to the base URL. `urlparse` however treats a `//` at the start of a string as a URI without a scheme, and then treats the next part as the hostname. `urljoin` will then use that hostname from the second part as the hostname replacing the original one from the request. This vulnerability is patched in WebOb version 1.8.8.

    Published: 14 Aug 2024
    10
    Critical

    CVE-2024-42472

    Last Modified: 19 Aug 2025

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on integrity and confidentiality. When `persistent=subdir` is used in the application permissions (represented as `--persist=subdir` in the command-line interface), that means that an application which otherwise doesn't have access to the real user home directory will see an empty home directory with a writeable subdirectory `subdir`. Behind the scenes, this directory is actually a bind mount and the data is stored in the per-application directory as `~/.var/app/$APPID/subdir`. This allows existing apps that are not aware of the per-application directory to still work as intended without general home directory access. However, the application does have write access to the application directory `~/.var/app/$APPID` where this directory is stored. If the source directory for the `persistent`/`--persist` option is replaced by a symlink, then the next time the application is started, the bind mount will follow the symlink and mount whatever it points to into the sandbox. Partial protection against this vulnerability can be provided by patching Flatpak using the patches in commits ceec2ffc and 98f79773. However, this leaves a race condition that could be exploited by two instances of a malicious app running in parallel. Closing the race condition requires updating or patching the version of bubblewrap that is used by Flatpak to add the new `--bind-fd` option using the patch and then patching Flatpak to use it. If Flatpak has been configured at build-time with `-Dsystem_bubblewrap=bwrap` (1.15.x) or `--with-system-bubblewrap=bwrap` (1.14.x or older), or a similar option, then the version of bubblewrap that needs to be patched is a system copy that is distributed separately, typically `/usr/bin/bwrap`. This configuration is the one that is typically used in Linux distributions. If Flatpak has been configured at build-time with `-Dsystem_bubblewrap=` (1.15.x) or with `--without-system-bubblewrap` (1.14.x or older), then it is the bundled version of bubblewrap that is included with Flatpak that must be patched. This is typically installed as `/usr/libexec/flatpak-bwrap`. This configuration is the default when building from source code. For the 1.14.x stable branch, these changes are included in Flatpak 1.14.10. The bundled version of bubblewrap included in this release has been updated to 0.6.3. For the 1.15.x development branch, these changes are included in Flatpak 1.15.10. The bundled version of bubblewrap in this release is a Meson "wrap" subproject, which has been updated to 0.10.0. The 1.12.x and 1.10.x branches will not be updated for this vulnerability. Long-term support OS distributions should backport the individual changes into their versions of Flatpak and bubblewrap, or update to newer versions if their stability policy allows it. As a workaround, avoid using applications using the `persistent` (`--persist`) permission.

    Published: 14 Aug 2024
    5.7
    Medium

    CVE-2024-7347

    Last Modified: 3 Nov 2025

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 14 Aug 2024
    5.3
    Medium

    CVE-2024-7752

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /update_medicine.php. The manipulation of the argument medicine_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38163

    Last Modified: 10 Jul 2025

    Windows Update Stack Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    5.3
    Medium

    CVE-2024-7751

    Last Modified: 19 Aug 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /update_medicine.php. The manipulation of the argument hidden_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    5.3
    Medium

    CVE-2024-7750

    Last Modified: 19 Aug 2024

    A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /medicines.php. The manipulation of the argument medicine_name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    9.8
    Critical

    CVE-2024-28986

    Last Modified: 27 Oct 2025

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

    Published: 13 Aug 2024
    5.3
    Medium

    CVE-2024-7749

    Last Modified: 22 Nov 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument account_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    5.3
    Medium

    CVE-2024-7748

    Last Modified: 22 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delete-account.php. The manipulation of the argument account leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7743

    Last Modified: 21 Aug 2024

    A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of the file /api/file/downloadUrl of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7742

    Last Modified: 21 Aug 2024

    A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7741

    Last Modified: 21 Aug 2024

    A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component API Endpoint. The manipulation of the argument file leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7740

    Last Modified: 21 Aug 2024

    A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /api/test/download of the component API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7739

    Last Modified: 2 Sept 2025

    A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    4.8
    Medium

    CVE-2024-7738

    Last Modified: 2 Sept 2025

    A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    9.8
    Critical

    CVE-2024-7593

    Last Modified: 14 May 2026

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

    Published: 13 Aug 2024
    8.3
    High

    CVE-2024-7570

    Last Modified: 6 Sept 2024

    Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.

    Published: 13 Aug 2024
    9.6
    Critical

    CVE-2024-7569

    Last Modified: 6 Sept 2024

    An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

    Published: 13 Aug 2024
    5.3
    Medium

    CVE-2024-7733

    Last Modified: 12 Sept 2024

    A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Aug 2024
    6.9
    Medium

    CVE-2024-7567

    Last Modified: 15 Apr 2026

    A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.

    Published: 13 Aug 2024
    5.4
    Medium

    CVE-2024-6079

    Last Modified: 15 Apr 2026

    A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack.

    Published: 13 Aug 2024
    —
    Unknown

    CVE-2024-7757

    Last Modified: 21 Aug 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 13 Aug 2024
    7.5
    High

    CVE-2024-37968

    Last Modified: 10 Jul 2025

    Windows DNS Spoofing Vulnerability

    Published: 13 Aug 2024
    9.1
    Critical

    CVE-2024-38109

    Last Modified: 10 Jul 2025

    An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

    Published: 13 Aug 2024
    6.8
    Medium

    CVE-2024-38223

    Last Modified: 10 Jul 2025

    Windows Initial Machine Configuration Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38215

    Last Modified: 10 Jul 2025

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    6.5
    Medium

    CVE-2024-38214

    Last Modified: 10 Jul 2025

    Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

    Published: 13 Aug 2024
    8.8
    High

    CVE-2024-38120

    Last Modified: 10 Jul 2025

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    8.2
    High

    CVE-2024-38211

    Last Modified: 10 Jul 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38195

    Last Modified: 10 Jul 2025

    Azure CycleCloud Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    8.8
    High

    CVE-2024-38189

    Last Modified: 28 Oct 2025

    Microsoft Project Remote Code Execution Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38187

    Last Modified: 10 Jul 2025

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024
    7.8
    High

    CVE-2024-38186

    Last Modified: 10 Jul 2025

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

    Published: 13 Aug 2024