CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-42481

    Last Modified: 16 Sept 2024

    Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting on createFolder. createFile), skyportd in a lot of cases will cause 100% CPU usage and an OOM, probably crashing the system. This is fixed in 0.2.2.

    Published: 12 Aug 2024
    8.1
    High

    CVE-2024-42480

    Last Modified: 16 Aug 2024

    Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.

    Published: 12 Aug 2024
    10
    Critical

    CVE-2024-42479

    Last Modified: 27 Apr 2026

    llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561.

    Published: 12 Aug 2024
    6.1
    Medium

    CVE-2024-21550

    Last Modified: 13 Aug 2024

    SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.

    Published: 12 Aug 2024
    10
    Critical

    CVE-2024-6917

    Last Modified: 3 Jun 2026

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection. This issue affects Veribase Order Management: before v4.010.2.

    Published: 12 Aug 2024
    9.8
    Critical

    CVE-2024-38530

    Last Modified: 13 Aug 2024

    The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.

    Published: 12 Aug 2024
    6.4
    Medium

    CVE-2024-6639

    Last Modified: 15 Apr 2026

    The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Aug 2024
    9.9
    Critical

    CVE-2024-6684

    Last Modified: 3 Jun 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authentication Bypass. This issue affects inohom Nova Panel N7: through 1.9.9.6. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 12 Aug 2024
    9.1
    Critical

    CVE-2024-42167

    Last Modified: 29 Aug 2024

    The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious organisationname.

    Published: 12 Aug 2024
    9.1
    Critical

    CVE-2024-42166

    Last Modified: 29 Aug 2024

    The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an application with a malicious name.

    Published: 12 Aug 2024
    6.3
    Medium

    CVE-2024-42165

    Last Modified: 29 Aug 2024

    Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation link.

    Published: 12 Aug 2024
    4.3
    Medium

    CVE-2024-42164

    Last Modified: 29 Aug 2024

    Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-42163

    Last Modified: 29 Aug 2024

    Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link.

    Published: 12 Aug 2024
    6.5
    Medium

    CVE-2024-6758

    Last Modified: 22 Aug 2025

    Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized protection assignments.

    Published: 12 Aug 2024
    6.5
    Medium

    CVE-2024-7700

    Last Modified: 20 Nov 2025

    A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration, potentially allowing unauthorized command execution during host registration. Although this issue requires user interaction to execute injected commands, it poses a significant risk if an unsuspecting user runs the generated registration script.

    Published: 12 Aug 2024
    7.5
    High

    CVE-2024-7697

    Last Modified: 13 Nov 2025

    Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-36034

    Last Modified: 16 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-36035

    Last Modified: 16 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-36518

    Last Modified: 21 Nov 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-5487

    Last Modified: 16 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

    Published: 12 Aug 2024
    8.3
    High

    CVE-2024-5527

    Last Modified: 16 Aug 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-5651

    Last Modified: 15 Apr 2026

    A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted FenceAgentsRemediation for a fence agent supporting  --ssh-path/--telnet-path arguments to execute arbitrary commands on the operator's pod. This RCE leads to a privilege escalation, first as the service account running the operator, then to another service account with cluster-admin privileges.

    Published: 12 Aug 2024
    7.2
    High

    CVE-2024-7694

    Last Modified: 18 Feb 2026

    ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

    Published: 12 Aug 2024
    7.5
    High

    CVE-2024-7693

    Last Modified: 6 Sept 2024

    Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the remote server.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-7686

    Last Modified: 20 Aug 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file register_case.php. The manipulation of the argument title/description/opposite_lawyer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-7685

    Last Modified: 20 Aug 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file adds.php. The manipulation of the argument name/dob/email/mobile/address leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-7684

    Last Modified: 20 Aug 2024

    A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add_act.php. The manipulation of the argument aname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-7683

    Last Modified: 20 Aug 2024

    A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file addcase_stage.php. The manipulation of the argument cname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Aug 2024
    6.9
    Medium

    CVE-2024-7682

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Job Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file rw_i_nat.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Aug 2024
    8.2
    High

    CVE-2024-36877

    Last Modified: 15 Apr 2026

    Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3. Motherboard's with the following chipsets are affected: Intel 300, Intel 400, Intel 500, Intel 600, Intel 700, AMD 300, AMD 400, AMD 500, AMD 600 and AMD 700.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2023-48171

    Last Modified: 18 Sept 2024

    An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

    Published: 12 Aug 2024
    7.2
    High

    CVE-2024-41710

    Last Modified: 5 Nov 2025

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

    Published: 12 Aug 2024
    8.1
    High

    CVE-2024-41651

    Last Modified: 9 Oct 2024

    An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).

    Published: 12 Aug 2024
    5.9
    Medium

    CVE-2024-41909

    Last Modified: 27 Mar 2025

    Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42626

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42632

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42742

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-42477

    Last Modified: 27 Apr 2026

    llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in b3561.

    Published: 12 Aug 2024
    7.8
    High

    CVE-2024-27442

    Last Modified: 13 Aug 2024

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privileges from the zimbra user to root, because of improper handling of input arguments. An attacker can execute arbitrary commands with elevated privileges, leading to local privilege escalation.

    Published: 12 Aug 2024
    5.4
    Medium

    CVE-2024-33533

    Last Modified: 13 Mar 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file and crafting a URL containing its location in the packages parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.

    Published: 12 Aug 2024
    8.6
    High

    CVE-2024-40500

    Last Modified: 5 Dec 2025

    Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.

    Published: 12 Aug 2024
    6.1
    Medium

    CVE-2024-27443

    Last Modified: 31 Oct 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

    Published: 12 Aug 2024
    7.5
    High

    CVE-2024-33535

    Last Modified: 19 Mar 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages parameter. Attackers can exploit this flaw to include arbitrary local files without authentication, potentially leading to unauthorized access to sensitive information. The vulnerability is limited to files within a specific directory.

    Published: 12 Aug 2024
    5.4
    Medium

    CVE-2024-33536

    Last Modified: 25 Mar 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of another user's browser session. By uploading a malicious JavaScript file, accessible externally, and crafting a URL containing its location in the res parameter, the attacker can exploit this vulnerability. Subsequently, when another user visits the crafted URL, the malicious JavaScript code is executed.

    Published: 12 Aug 2024
    7.1
    High

    CVE-2024-42258

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: use !CONFIG_64BIT to relax huge page alignment on 32 bit machines Yves-Alexis Perez reported commit 4ef9ad19e176 ("mm: huge_memory: don't force huge page alignment on 32 bit") didn't work for x86_32 [1]. It is because x86_32 uses CONFIG_X86_32 instead of CONFIG_32BIT. !CONFIG_64BIT should cover all 32 bit machines. [1] https://lore.kernel.org/linux-mm/CAHbLzkr1LwH3pcTgM+aGQ31ip2bKqiqEQ8=FQB+t2c3dhNKNHA@mail.gmail.com/

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-39091

    Last Modified: 13 Aug 2024

    An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-41475

    Last Modified: 18 Sept 2024

    Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

    Published: 12 Aug 2024
    5.3
    Medium

    CVE-2024-42478

    Last Modified: 27 Apr 2026

    llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address reading. This vulnerability is fixed in b3561.

    Published: 12 Aug 2024
    9.8
    Critical

    CVE-2024-42520

    Last Modified: 13 Aug 2024

    TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.

    Published: 12 Aug 2024
    9.8
    Critical

    CVE-2024-42543

    Last Modified: 13 Aug 2024

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

    Published: 12 Aug 2024