CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-7536

    Last Modified: 12 Aug 2024

    Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7535

    Last Modified: 24 Oct 2024

    Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7534

    Last Modified: 15 Oct 2024

    Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7533

    Last Modified: 12 Aug 2024

    Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7532

    Last Modified: 12 Aug 2024

    Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-42400

    Last Modified: 13 Mar 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-42399

    Last Modified: 13 Mar 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-42398

    Last Modified: 24 Mar 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-42393

    Last Modified: 12 Aug 2024

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-42394

    Last Modified: 12 Aug 2024

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-42395

    Last Modified: 12 Aug 2024

    There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-42396

    Last Modified: 25 Mar 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-42397

    Last Modified: 19 Mar 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 6 Aug 2024
    6.3
    Medium

    CVE-2024-41677

    Last Modified: 12 Aug 2024

    Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found in the `render-ssr.ts` file. It sometimes causes the situation that the final DOM tree rendered on browsers is different from what Qwik expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS). This has been resolved in qwik version 1.6.0 and @builder.io/qwik version 1.7.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Aug 2024
    —
    Unknown

    CVE-2024-7566

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 6 Aug 2024
    7.7
    High

    CVE-2024-42347

    Last Modified: 12 Aug 2024

    matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Aug 2024
    6.2
    Medium

    CVE-2024-42358

    Last Modified: 12 Aug 2024

    PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously crafted TTF files can cause the program to utilize 100% of the Memory and enter an infinite loop. This can also lead to a heap-buffer-overflow vulnerability. An infinite loop occurs in the read_camp function by nGroups value. The ttf.h library is vulnerable. A value called nGroups is extracted from the file, and by changing that value, you can cause the program to utilize 100% of the Memory and enter an infinite loop. If the value of nGroups in the file is small, an infinite loop will not occur. This library, whether used as a standalone binary or as part of another application, is vulnerable to DOS attacks when parsing certain types of files. Automated systems, including web servers that use this code to convert PDF submissions into plaintext, can be DOSed if an attacker uploads a malicious TTF file. This issue has been addressed in release version 1.3.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 6 Aug 2024
    8.5
    High

    CVE-2024-7502

    Last Modified: 12 Aug 2024

    A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-43111

    Last Modified: 19 Aug 2026

    Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-43113

    Last Modified: 19 Aug 2026

    The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-43112

    Last Modified: 19 Aug 2026

    Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-7564

    Last Modified: 7 Aug 2024

    Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the get_response_json_result endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-24680.

    Published: 6 Aug 2024
    5.7
    Medium

    CVE-2023-28806

    Last Modified: 7 Aug 2024

    An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.

    Published: 6 Aug 2024
    4.3
    Medium

    CVE-2024-7003

    Last Modified: 7 Aug 2024

    Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7000

    Last Modified: 7 Aug 2024

    Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    4.3
    Medium

    CVE-2024-6999

    Last Modified: 14 Mar 2025

    Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6998

    Last Modified: 7 Aug 2024

    Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6997

    Last Modified: 13 Aug 2024

    Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    3.1
    Low

    CVE-2024-6996

    Last Modified: 13 Mar 2025

    Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    4.7
    Medium

    CVE-2024-6995

    Last Modified: 7 Aug 2024

    Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6994

    Last Modified: 7 Aug 2024

    Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6989

    Last Modified: 7 Aug 2024

    Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6988

    Last Modified: 7 Aug 2024

    Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Aug 2024
    7
    High

    CVE-2024-23483

    Last Modified: 7 Aug 2024

    An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.

    Published: 6 Aug 2024
    6.4
    Medium

    CVE-2024-23460

    Last Modified: 7 Aug 2024

    The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6720

    Last Modified: 28 Oct 2024

    The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 6 Aug 2024
    7.2
    High

    CVE-2024-23464

    Last Modified: 7 Aug 2024

    In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

    Published: 6 Aug 2024
    7.3
    High

    CVE-2024-23458

    Last Modified: 7 Aug 2024

    While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.

    Published: 6 Aug 2024
    7.8
    High

    CVE-2024-23456

    Last Modified: 7 Aug 2024

    Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

    Published: 6 Aug 2024
    4.3
    Medium

    CVE-2024-39751

    Last Modified: 29 Aug 2024

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 297429

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7552

    Last Modified: 7 Aug 2024

    A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.

    Published: 6 Aug 2024
    5.4
    Medium

    CVE-2024-41911

    Last Modified: 2 Oct 2025

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-41910

    Last Modified: 2 Oct 2025

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-41913

    Last Modified: 2 Oct 2025

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33994

    Last Modified: 22 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33993

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.

    Published: 6 Aug 2024
    6.3
    Medium

    CVE-2024-6357

    Last Modified: 19 Aug 2024

    Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

    Published: 6 Aug 2024
    6.4
    Medium

    CVE-2024-6359

    Last Modified: 19 Aug 2024

    Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

    Published: 6 Aug 2024
    6.3
    Medium

    CVE-2024-6358

    Last Modified: 19 Aug 2024

    Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33992

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.

    Published: 6 Aug 2024