CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-6201

    Last Modified: 25 Mar 2025

    HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

    Published: 6 Aug 2024
    8
    High

    CVE-2024-6200

    Last Modified: 29 Aug 2024

    HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-5709

    Last Modified: 8 Apr 2026

    The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administrator, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 6 Aug 2024
    6.4
    Medium

    CVE-2024-5708

    Last Modified: 8 Apr 2026

    The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, and with post permissions granted by an Administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-39817

    Last Modified: 18 Mar 2025

    Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7506

    Last Modified: 11 Sept 2024

    A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The manipulation of the argument bgimg leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273649 was assigned to this vulnerability.

    Published: 6 Aug 2024
    6.9
    Medium

    CVE-2024-7505

    Last Modified: 11 Sept 2024

    A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-28962

    Last Modified: 19 Aug 2024

    Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

    Published: 6 Aug 2024
    4.2
    Medium

    CVE-2024-7009

    Last Modified: 19 Aug 2024

    Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.

    Published: 6 Aug 2024
    5.4
    Medium

    CVE-2024-7008

    Last Modified: 19 Aug 2024

    Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-6782

    Last Modified: 15 Apr 2026

    Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-6781

    Last Modified: 19 Aug 2024

    Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7500

    Last Modified: 11 Sept 2024

    A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273626 is the identifier assigned to this vulnerability.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7499

    Last Modified: 19 Aug 2024

    A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file flights.php. The manipulation of the argument departure_airport_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273625 was assigned to this vulnerability.

    Published: 6 Aug 2024
    6.9
    Medium

    CVE-2024-7498

    Last Modified: 19 Aug 2024

    A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273624.

    Published: 6 Aug 2024
    8.6
    High

    CVE-2024-5828

    Last Modified: 8 Jan 2025

    Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

    Published: 6 Aug 2024
    6.7
    Medium

    CVE-2024-5963

    Last Modified: 15 Apr 2026

    Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7497

    Last Modified: 19 Aug 2024

    A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273623.

    Published: 6 Aug 2024
    7.2
    High

    CVE-2024-7485

    Last Modified: 15 Apr 2026

    The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2023-5000

    Last Modified: 15 Apr 2026

    The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-6315

    Last Modified: 15 Apr 2026

    The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all versions up to, and including, 1.0.65. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 6 Aug 2024
    7.2
    High

    CVE-2024-7484

    Last Modified: 8 Apr 2026

    The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7496

    Last Modified: 19 Aug 2024

    A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273622 is the identifier assigned to this vulnerability.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-7495

    Last Modified: 19 Aug 2024

    A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273621 was assigned to this vulnerability.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7530

    Last Modified: 12 Aug 2024

    Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

    Published: 6 Aug 2024
    5.3
    Medium

    CVE-2024-39229

    Last Modified: 21 Nov 2024

    An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.

    Published: 6 Aug 2024
    7.8
    High

    CVE-2024-42219

    Last Modified: 12 Aug 2024

    1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2023-40819

    Last Modified: 12 Aug 2024

    ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

    Published: 6 Aug 2024
    6.3
    Medium

    CVE-2024-7246

    Last Modified: 22 Jul 2025

    It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's also possible to use this vulnerability to leak other clients HTTP header keys, but not values. This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table. Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7521

    Last Modified: 12 Aug 2024

    Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-7526

    Last Modified: 17 Sept 2024

    ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-7531

    Last Modified: 19 Mar 2025

    Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

    Published: 6 Aug 2024
    5.5
    Medium

    CVE-2024-36424

    Last Modified: 13 Mar 2025

    K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

    Published: 6 Aug 2024
    7.2
    High

    CVE-2024-28739

    Last Modified: 12 Aug 2024

    An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

    Published: 6 Aug 2024
    9.6
    Critical

    CVE-2024-28740

    Last Modified: 21 Aug 2024

    Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.

    Published: 6 Aug 2024
    9.1
    Critical

    CVE-2024-30170

    Last Modified: 12 Aug 2024

    PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,

    Published: 6 Aug 2024
    9.1
    Critical

    CVE-2024-33897

    Last Modified: 21 Nov 2024

    A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-39225

    Last Modified: 15 Aug 2024

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-39226

    Last Modified: 12 Nov 2024

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to manipulate routers by passing malicious shell commands through the s2s API.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-39227

    Last Modified: 15 Aug 2024

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint /cgi-bin/glc. This vulnerability allows unauthenticated attackers to execute arbitrary code or possibly a directory traversal via crafted JSON data.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-39228

    Last Modified: 15 Aug 2024

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the interface check_ovpn_client_config and check_config.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-40101

    Last Modified: 25 Mar 2025

    A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

    Published: 6 Aug 2024
    7.8
    High

    CVE-2024-41226

    Last Modified: 3 Sept 2024

    A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.

    Published: 6 Aug 2024
    9.1
    Critical

    CVE-2024-41270

    Last Modified: 12 Aug 2024

    An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-41333

    Last Modified: 13 Mar 2025

    A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-41616

    Last Modified: 7 Aug 2024

    D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

    Published: 6 Aug 2024
    4.7
    Medium

    CVE-2024-42218

    Last Modified: 12 Aug 2024

    1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-7518

    Last Modified: 29 Oct 2024

    Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

    Published: 6 Aug 2024
    9.6
    Critical

    CVE-2024-7519

    Last Modified: 12 Aug 2024

    Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7520

    Last Modified: 24 Mar 2025

    A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

    Published: 6 Aug 2024