CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-7523

    Last Modified: 19 Aug 2026

    A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7522

    Last Modified: 12 Aug 2024

    Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-7524

    Last Modified: 25 Mar 2025

    Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

    Published: 6 Aug 2024
    8.1
    High

    CVE-2024-7525

    Last Modified: 12 Aug 2024

    It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7527

    Last Modified: 18 Mar 2025

    Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    8.8
    High

    CVE-2024-7528

    Last Modified: 12 Aug 2024

    Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

    Published: 6 Aug 2024
    6.5
    Medium

    CVE-2024-7529

    Last Modified: 12 Aug 2024

    The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

    Published: 6 Aug 2024
    7.8
    High

    CVE-2024-7547

    Last Modified: 19 Aug 2024

    oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of SMS PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23460.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7546

    Last Modified: 29 Aug 2024

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23459.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7545

    Last Modified: 19 Aug 2024

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23458.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7544

    Last Modified: 19 Aug 2024

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23457.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7543

    Last Modified: 19 Aug 2024

    oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23456.

    Published: 5 Aug 2024
    3.3
    Low

    CVE-2024-7542

    Last Modified: 29 Aug 2024

    oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMGR commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23309.

    Published: 5 Aug 2024
    3.3
    Low

    CVE-2024-7541

    Last Modified: 29 Aug 2024

    oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMT commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23308.

    Published: 5 Aug 2024
    3.3
    Low

    CVE-2024-7540

    Last Modified: 29 Aug 2024

    oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMGL commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23307.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7539

    Last Modified: 29 Aug 2024

    oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CUSD commands. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-23195.

    Published: 5 Aug 2024
    7.8
    High

    CVE-2024-7538

    Last Modified: 29 Aug 2024

    oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT Commands. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-23190.

    Published: 5 Aug 2024
    5.5
    Medium

    CVE-2024-7537

    Last Modified: 29 Aug 2024

    oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SMS message lists. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23157.

    Published: 5 Aug 2024
    5.3
    Medium

    CVE-2024-7494

    Last Modified: 19 Aug 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.0. Affected by this issue is some unknown functionality of the file /new_prescription.php. The manipulation of the argument patient leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273620.

    Published: 5 Aug 2024
    8.6
    High

    CVE-2024-42352

    Last Modified: 19 Sept 2024

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly parsed, allowing an attacker to change the scheme and host of the request. This leads to SSRF, and could potentially lead to sensitive data exposure. The `new URL` constructor is used to parse the final path. This constructor can be passed a relative scheme or path in order to change the host the request is sent to. This constructor is also very tolerant of poorly formatted URLs. As a result we can pass a path prefixed with the string `http:`. This has the effect of changing the scheme to HTTP. We can then subsequently pass a new host, for example `http:127.0.0.1:8080`. This would allow us to send requests to a local server. This issue has been addressed in release version 1.4.5 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    8.8
    High

    CVE-2024-34344

    Last Modified: 19 Sept 2024

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them to execute arbitrary commands. Users who open a malicious web page in the browser while running the test locally are affected by this vulnerability, which results in the remote code execution from the malicious web page. Since web pages can send requests to arbitrary addresses, a malicious web page can repeatedly try to exploit this vulnerability, which then triggers the exploit when the test server starts.

    Published: 5 Aug 2024
    6.3
    Medium

    CVE-2024-34343

    Last Modified: 19 Sept 2024

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo` function attempts to blockthe `javascript:` protocol, but does not correctly use API's provided by `unjs/ufo`. This library also contains parsing discrepancies. The function first tests to see if the specified URL has a protocol. This uses the unjs/ufo package for URL parsing. This function works effectively, and returns true for a javascript: protocol. After this, the URL is parsed using the parseURL function. This function will refuse to parse poorly formatted URLs. Parsing javascript:alert(1) returns null/"" for all values. Next, the protocol of the URL is then checked using the isScriptProtocol function. This function simply checks the input against a list of protocols, and does not perform any parsing. The combination of refusing to parse poorly formatted URLs, and not performing additional parsing means that script checks fail as no protocol can be found. Even if a protocol was identified, whitespace is not stripped in the parseURL implementation, bypassing the isScriptProtocol checks. Certain special protocols are identified at the top of parseURL. Inserting a newline or tab into this sequence will block the special protocol check, and bypass the latter checks. This ONLY has impact after SSR has occured, the `javascript:` protocol within a location header does not trigger XSS. This issue has been addressed in release version 3.12.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    8.8
    High

    CVE-2024-23657

    Last Modified: 20 Sept 2024

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the WebSocket handler, an attacker is able to interact with a locally running devtools instance and exfiltrate data abusing this vulnerability. In certain configurations an attacker could leak the devtools authentication token and then abuse other RPC functions to achieve RCE. The `getTextAssetContent` function does not check for path traversals, this could allow an attacker to read arbitrary files over the RPC WebSocket. The WebSocket server does not check the origin of the request leading to cross-site-websocket-hijacking. This may be intentional to allow certain configurations to work correctly. Nuxt Devtools authentication tokens are placed within the home directory of the current user. The malicious webpage can connect to the Devtools WebSocket, perform a directory traversal brute force to find the authentication token, then use the *authenticated* `writeStaticAssets` function to create a new Component, Nitro Handler or `app.vue` file which will run automatically as the file is changed. This vulnerability has been addressed in release version 1.3.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    3.9
    Low

    CVE-2024-41811

    Last Modified: 15 Apr 2026

    ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.

    Published: 5 Aug 2024
    5.4
    Medium

    CVE-2024-41816

    Last Modified: 7 Feb 2025

    Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    6
    Medium

    CVE-2024-41820

    Last Modified: 15 Apr 2026

    Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access the worker node which has kubean's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation. This issue has been addressed in release version 0.18.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    3.8
    Low

    CVE-2024-41960

    Last Modified: 19 Sept 2024

    mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is executed whenever the configuration page is viewed, enabling the attacker to execute arbitrary scripts in the context of the user's browser. This could lead to data theft, or further exploitation. This issue has been addressed in the `2024-07` release. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    7.6
    High

    CVE-2024-41959

    Last Modified: 19 Sept 2024

    mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to run malicious scripts in the context of the user's browser. This could lead to unauthorized actions, data theft, or further exploitation of the affected system. This issue has been addressed in the `2024-07` release. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    6.6
    Medium

    CVE-2024-41958

    Last Modified: 20 Sept 2024

    mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other accounts that are otherwise secured with 2FA. To exploit this vulnerability, the attacker must first have access to an account within the system and possess the credentials of the target account that has 2FA enabled. By leveraging these credentials, the attacker can circumvent the 2FA process and gain access to the protected account. This issue has been addressed in the `2024-07` release. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    3
    Low

    CVE-2024-42350

    Last Modified: 15 Apr 2026

    Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a `ThirdPartyBlock` request can be sent, providing only the necessary info to generate a third-party block and to sign it: 1. the public key of the previous block (used in the signature), 2. the public keys part of the token symbol table (for public key interning in datalog expressions). A third-part block request forged by a malicious user can trick the third-party authority into generating datalog trusting the wrong keypair. Tokens with third-party blocks containing `trusted` annotations generated through a third party block request. This has been addressed in version 4 of the specification. Users are advised to update their implementations to conform. There are no known workarounds for this vulnerability.

    Published: 5 Aug 2024
    9.3
    Critical

    CVE-2024-6915

    Last Modified: 15 Apr 2026

    JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

    Published: 5 Aug 2024
    7.3
    High

    CVE-2024-6361

    Last Modified: 1 Nov 2024

    Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33034

    Last Modified: 20 Nov 2024

    Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33028

    Last Modified: 20 Nov 2024

    Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33027

    Last Modified: 20 Nov 2024

    Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33026

    Last Modified: 20 Nov 2024

    Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33025

    Last Modified: 20 Nov 2024

    Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33024

    Last Modified: 20 Nov 2024

    Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33023

    Last Modified: 20 Nov 2024

    Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33022

    Last Modified: 20 Nov 2024

    Memory corruption while allocating memory in HGSL driver.

    Published: 5 Aug 2024
    8.4
    High

    CVE-2024-33021

    Last Modified: 20 Nov 2024

    Memory corruption while processing IOCTL call to set metainfo.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33020

    Last Modified: 20 Nov 2024

    Transient DOS while processing TID-to-link mapping IE elements.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33019

    Last Modified: 20 Nov 2024

    Transient DOS while parsing the received TID-to-link mapping action frame.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33018

    Last Modified: 20 Nov 2024

    Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33015

    Last Modified: 20 Nov 2024

    Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33014

    Last Modified: 20 Nov 2024

    Transient DOS while parsing ESP IE from beacon/probe response frame.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33013

    Last Modified: 26 Nov 2024

    Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33012

    Last Modified: 26 Nov 2024

    Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33011

    Last Modified: 26 Nov 2024

    Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

    Published: 5 Aug 2024
    7.5
    High

    CVE-2024-33010

    Last Modified: 26 Nov 2024

    Transient DOS while parsing fragments of MBSSID IE from beacon frame.

    Published: 5 Aug 2024