CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-7578

    Last Modified: 28 Aug 2024

    A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the argument cmd leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Aug 2024
    4.9
    Medium

    CVE-2024-7355

    Last Modified: 8 Apr 2026

    The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this can only be exploited by administrators, but the ability to use and configure charts can be extended to subscribers.

    Published: 7 Aug 2024
    5.4
    Medium

    CVE-2024-7353

    Last Modified: 15 Apr 2026

    The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Aug 2024
    8.5
    High

    CVE-2024-6522

    Last Modified: 8 Apr 2026

    The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 7 Aug 2024
    7.1
    High

    CVE-2024-7267

    Last Modified: 17 Mar 2025

    Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP infrastructure and credentials. This issue affects EZD RP all versions before 19.6

    Published: 7 Aug 2024
    7.1
    High

    CVE-2024-7266

    Last Modified: 25 Mar 2025

    Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

    Published: 7 Aug 2024
    8.7
    High

    CVE-2024-7265

    Last Modified: 17 Mar 2025

    Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

    Published: 7 Aug 2024
    7.3
    High

    CVE-2024-7553

    Last Modified: 19 Sept 2024

    Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to 1.26.2 and MongoDB PHP Driver versions prior to 1.18.1. Required Configuration: Only environments with Windows as the underlying operating system is affected by this issue

    Published: 7 Aug 2024
    7.2
    High

    CVE-2024-42062

    Last Modified: 21 Nov 2024

    CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission validation issue that affects Apache CloudStack versions 4.10.0 up to 4.19.1.0, domain admin accounts were found to be able to query all registered account-users API and secret keys in an environment, including that of a root admin. An attacker who has domain admin access can exploit this to gain root admin and other-account privileges and perform malicious operations that can result in compromise of resources integrity and confidentiality, data loss, denial of service and availability of CloudStack managed infrastructure. Users are recommended to upgrade to Apache CloudStack 4.18.2.3 or 4.19.1.1, or later, which addresses this issue. Additionally, all account-user API and secret keys should be regenerated.

    Published: 7 Aug 2024
    4.3
    Medium

    CVE-2024-42222

    Last Modified: 14 Mar 2025

    In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1.

    Published: 7 Aug 2024
    6.1
    Medium

    CVE-2024-6494

    Last Modified: 11 Apr 2025

    The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.

    Published: 7 Aug 2024
    4.8
    Medium

    CVE-2024-3973

    Last Modified: 28 May 2025

    The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 7 Aug 2024
    9.8
    Critical

    CVE-2024-36130

    Last Modified: 13 Mar 2025

    An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

    Published: 7 Aug 2024
    8.8
    High

    CVE-2024-36131

    Last Modified: 21 Aug 2024

    An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

    Published: 7 Aug 2024
    7.5
    High

    CVE-2024-36132

    Last Modified: 19 Mar 2025

    Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-37403

    Last Modified: 25 Mar 2025

    Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.

    Published: 7 Aug 2024
    6.5
    Medium

    CVE-2024-34788

    Last Modified: 12 Aug 2024

    An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

    Published: 7 Aug 2024
    2.8
    Low

    CVE-2024-43167

    Last Modified: 15 Apr 2026

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. When certain API functions such as ub_ctx_set_fwd and ub_ctx_resolvconf are called in a particular order, the program attempts to read from a NULL pointer, leading to a crash. This issue can result in a denial of service by causing the application to terminate unexpectedly.

    Published: 7 Aug 2024
    4.8
    Medium

    CVE-2024-43168

    Last Modified: 15 Apr 2026

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further information about the claim, and suggests that affected Red Hat customers refer to available Red Hat documentation or support channels. ORIGINAL DESCRIPTION: A heap-buffer-overflow flaw was found in the cfg_mark_ports function within Unbound's config_file.c, which can lead to memory corruption. This issue could allow an attacker with local access to provide specially crafted input, potentially causing the application to crash or allowing arbitrary code execution. This could result in a denial of service or unauthorized actions on the system.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34636

    Last Modified: 29 Aug 2024

    Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34635

    Last Modified: 9 Aug 2024

    Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34634

    Last Modified: 9 Aug 2024

    Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34633

    Last Modified: 9 Aug 2024

    Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34632

    Last Modified: 9 Aug 2024

    Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34631

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34630

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34629

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34628

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34627

    Last Modified: 9 Aug 2024

    Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34626

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34625

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34624

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    7.8
    High

    CVE-2024-34623

    Last Modified: 9 Aug 2024

    Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

    Published: 7 Aug 2024
    7.8
    High

    CVE-2024-34622

    Last Modified: 9 Aug 2024

    Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

    Published: 7 Aug 2024
    5.5
    Medium

    CVE-2024-34621

    Last Modified: 9 Aug 2024

    Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

    Published: 7 Aug 2024
    8.4
    High

    CVE-2024-34620

    Last Modified: 12 Aug 2024

    Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

    Published: 7 Aug 2024
    7.5
    High

    CVE-2024-34619

    Last Modified: 12 Aug 2024

    Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34618

    Last Modified: 12 Aug 2024

    Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34617

    Last Modified: 12 Aug 2024

    Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

    Published: 7 Aug 2024
    5.1
    Medium

    CVE-2024-34616

    Last Modified: 12 Aug 2024

    Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

    Published: 7 Aug 2024
    5.1
    Medium

    CVE-2024-34615

    Last Modified: 12 Aug 2024

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

    Published: 7 Aug 2024
    7.3
    High

    CVE-2024-34614

    Last Modified: 12 Aug 2024

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

    Published: 7 Aug 2024
    4
    Medium

    CVE-2024-34613

    Last Modified: 12 Aug 2024

    Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

    Published: 7 Aug 2024
    7.3
    High

    CVE-2024-34612

    Last Modified: 12 Aug 2024

    Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

    Published: 7 Aug 2024
    5.1
    Medium

    CVE-2024-34611

    Last Modified: 12 Aug 2024

    Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

    Published: 7 Aug 2024
    5.1
    Medium

    CVE-2024-34610

    Last Modified: 12 Aug 2024

    Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

    Published: 7 Aug 2024
    6.2
    Medium

    CVE-2024-34609

    Last Modified: 12 Aug 2024

    Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

    Published: 7 Aug 2024
    6.2
    Medium

    CVE-2024-34608

    Last Modified: 12 Aug 2024

    Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

    Published: 7 Aug 2024
    6.2
    Medium

    CVE-2024-34607

    Last Modified: 12 Aug 2024

    Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

    Published: 7 Aug 2024
    6.2
    Medium

    CVE-2024-34606

    Last Modified: 12 Aug 2024

    Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

    Published: 7 Aug 2024