CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-42545

    Last Modified: 13 Aug 2024

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.

    Published: 12 Aug 2024
    9.8
    Critical

    CVE-2024-42546

    Last Modified: 15 Aug 2024

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.

    Published: 12 Aug 2024
    9.8
    Critical

    CVE-2024-42547

    Last Modified: 13 Aug 2024

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42623

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42624

    Last Modified: 15 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42625

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42627

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42628

    Last Modified: 15 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42629

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42630

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42631

    Last Modified: 13 Aug 2024

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42741

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42743

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42744

    Last Modified: 15 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42745

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42747

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    8.8
    High

    CVE-2024-42748

    Last Modified: 13 Aug 2024

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

    Published: 12 Aug 2024
    6.9
    Medium

    CVE-2024-7681

    Last Modified: 15 Aug 2024

    A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7680

    Last Modified: 15 Aug 2024

    A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /incedit.php?id=4. The manipulation of the argument id/inccat/desc/date/amount leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7678

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_package. The manipulation of the argument name/description/training_duration leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7677

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7676

    Last Modified: 15 Aug 2024

    A vulnerability was found in Sourcecodester Car Driving School Management System 1.0. It has been classified as critical. Affected is the function save_package of the file /classes/Master.php?f=save_package. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7669

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This issue affects the function delete_enrollment of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7668

    Last Modified: 15 Aug 2024

    A vulnerability has been found in SourceCodester Car Driving School Management System 1.0 and classified as critical. This vulnerability affects the function delete_package of the file Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7667

    Last Modified: 15 Aug 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Car Driving School Management System 1.0. This affects the function delete_users of the file User.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7666

    Last Modified: 15 Aug 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Car Driving School Management System 1.0. Affected by this issue is some unknown functionality of the file view_package.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7665

    Last Modified: 15 Aug 2024

    A vulnerability classified as critical was found in SourceCodester Car Driving School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_package.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7664

    Last Modified: 15 Aug 2024

    A vulnerability classified as critical has been found in SourceCodester Car Driving School Management System 1.0. Affected is an unknown function of the file view_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7663

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    6.9
    Medium

    CVE-2024-7662

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects the function save_package of the file admin/packages/manag_package.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    6.9
    Medium

    CVE-2024-7661

    Last Modified: 15 Aug 2024

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the function save_users of the file admin/user/index.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    8.1
    High

    CVE-2024-7589

    Last Modified: 21 Nov 2024

    A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default). This signal handler executes in the context of the sshd(8)'s privileged code, which is not sandboxed and runs with full root privileges. This issue is another instance of the problem in CVE-2024-6387 addressed by FreeBSD-SA-24:04.openssh. The faulty code in this case is from the integration of blacklistd in OpenSSH in FreeBSD. As a result of calling functions that are not async-signal-safe in the privileged sshd(8) context, a race condition exists that a determined attacker may be able to exploit to allow an unauthenticated remote code execution as root.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7660

    Last Modified: 22 Nov 2024

    A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Add File Handler. The manipulation of the argument File Title/Uploaded By leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-6759

    Last Modified: 21 Nov 2024

    When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and related functions to return filesystem entries with names containing additional path components. The lack of validation described above gives rise to a confused deputy problem. For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory.

    Published: 11 Aug 2024
    7.5
    High

    CVE-2024-6760

    Last Modified: 21 Nov 2024

    A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

    Published: 11 Aug 2024
    6.3
    Medium

    CVE-2024-6640

    Last Modified: 15 Apr 2026

    In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo Request packet after a Neighbor Solicitation (NS) can trigger an Echo Reply. The packet has to come from the same host as the NS and have a zero as identifier to match the state created by the Neighbor Discovery and allow replies to be generated. ICMPv6 packets with identifier value of zero bypass firewall rules written on the assumption that the incoming packets are going to create a state in the state table.

    Published: 11 Aug 2024
    6.3
    Medium

    CVE-2024-7659

    Last Modified: 15 Aug 2024

    A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation leads to insufficiently random values. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version r1720 is able to address this issue. The name of the patch is aa27eb97edc2ff2b203f97e6675d7b5ba0a22a17. It is recommended to upgrade the affected component.

    Published: 11 Aug 2024
    6.9
    Medium

    CVE-2024-7658

    Last Modified: 13 Jan 2025

    A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component.

    Published: 11 Aug 2024
    5.3
    Medium

    CVE-2024-7657

    Last Modified: 15 Aug 2024

    A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2024
    9.3
    Critical

    CVE-2024-21876

    Last Modified: 11 Mar 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

    Published: 10 Aug 2024
    8.7
    High

    CVE-2024-21879

    Last Modified: 11 Mar 2025

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

    Published: 10 Aug 2024
    9.2
    Critical

    CVE-2024-21877

    Last Modified: 11 Mar 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.

    Published: 10 Aug 2024
    9.2
    Critical

    CVE-2024-21878

    Last Modified: 11 Mar 2025

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.

    Published: 10 Aug 2024
    8.6
    High

    CVE-2024-21880

    Last Modified: 11 Mar 2025

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x

    Published: 10 Aug 2024
    8.6
    High

    CVE-2024-21881

    Last Modified: 15 Apr 2026

    Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x

    Published: 10 Aug 2024
    5.4
    Medium

    CVE-2024-6134

    Last Modified: 8 May 2025

    The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 10 Aug 2024
    6.1
    Medium

    CVE-2024-7574

    Last Modified: 8 Apr 2026

    The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Aug 2024
    5.3
    Medium

    CVE-2024-5801

    Last Modified: 15 Apr 2026

    Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.

    Published: 10 Aug 2024
    8.3
    High

    CVE-2024-5800

    Last Modified: 19 Dec 2025

    Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.

    Published: 10 Aug 2024
    6.1
    Medium

    CVE-2024-7649

    Last Modified: 15 Apr 2026

    The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Aug 2024