CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-7409

    Last Modified: 31 Aug 2026

    A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-6704

    Last Modified: 8 Apr 2026

    The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.

    Published: 2 Aug 2024
    6.5
    Medium

    CVE-2024-7323

    Last Modified: 11 Sept 2024

    Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .

    Published: 2 Aug 2024
    8.7
    High

    CVE-2024-38879

    Last Modified: 3 Nov 2025

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication and directly access the exposed application.

    Published: 2 Aug 2024
    6.9
    Medium

    CVE-2024-38878

    Last Modified: 3 Nov 2025

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). Affected devices allow authenticated users to export diagnostics data. The corresponding API endpoint is susceptible to path traversal and could allow an authenticated attacker to download arbitrary files from the file system.

    Published: 2 Aug 2024
    8.3
    High

    CVE-2024-38877

    Last Modified: 3 Nov 2025

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Security Server R9.2 (All versions), Omnivise T3000 Terminal Server R9.2 (All versions), Omnivise T3000 Thin Client R9.2 (All versions), Omnivise T3000 Whitelisting Server R9.2 (All versions). The affected devices stores initial system credentials without sufficient protection. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss allowing the attacker to laterally move within the affected network.

    Published: 2 Aug 2024
    8.5
    High

    CVE-2024-38876

    Last Modified: 3 Nov 2025

    A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal Server R9.2 (All versions), Omnivise T3000 Thin Client R9.2 (All versions), Omnivise T3000 Whitelisting Server R9.2 (All versions). The affected application regularly executes user modifiable code as a privileged user. This could allow a local authenticated attacker to execute arbitrary code with elevated privileges.

    Published: 2 Aug 2024
    6.1
    Medium

    CVE-2024-7204

    Last Modified: 11 Sept 2024

    Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they will be subject to a Stored XSS attack.

    Published: 2 Aug 2024
    4.3
    Medium

    CVE-2024-40723

    Last Modified: 9 Aug 2024

    The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service.

    Published: 2 Aug 2024
    4.3
    Medium

    CVE-2024-40722

    Last Modified: 9 Aug 2024

    The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-40721

    Last Modified: 9 Aug 2024

    The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-40720

    Last Modified: 9 Aug 2024

    The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.

    Published: 2 Aug 2024
    6.5
    Medium

    CVE-2024-40719

    Last Modified: 9 Aug 2024

    The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-36268

    Last Modified: 21 Nov 2024

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/10251

    Published: 2 Aug 2024
    6.4
    Medium

    CVE-2024-4643

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2024
    4.9
    Medium

    CVE-2024-27182

    Last Modified: 27 Mar 2025

    In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-27181

    Last Modified: 3 Jun 2025

    In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.

    Published: 2 Aug 2024
    —
    Unknown

    CVE-2024-7403

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Aug 2024
    7.1
    High

    CVE-2024-38776

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7.

    Published: 2 Aug 2024
    7.8
    High

    CVE-2024-39392

    Last Modified: 2 Dec 2024

    InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 2 Aug 2024
    5.5
    Medium

    CVE-2024-39396

    Last Modified: 2 Dec 2024

    InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-3238

    Last Modified: 15 Apr 2026

    The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to delete arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please not the CSRF was patched in 5.0.28, however, adequate directory traversal protection wasn't introduced until 5.0.30.

    Published: 2 Aug 2024
    5.4
    Medium

    CVE-2024-5595

    Last Modified: 11 Apr 2025

    The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 2 Aug 2024
    6.4
    Medium

    CVE-2024-3827

    Last Modified: 8 Apr 2026

    The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-7389

    Last Modified: 8 Apr 2026

    The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.

    Published: 2 Aug 2024
    6.6
    Medium

    CVE-2024-38482

    Last Modified: 5 Sept 2024

    CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the database.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7378

    Last Modified: 9 Aug 2024

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_question.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273362 is the identifier assigned to this vulnerability.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7377

    Last Modified: 9 Aug 2024

    A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_result.php. The manipulation of the argument qid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273361 was assigned to this vulnerability.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-6567

    Last Modified: 8 Apr 2026

    The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website. The plugin vendor removed the test files, however, did not increment the version meaning this is inadequately patched in the same version that is affected.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7376

    Last Modified: 9 Aug 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected is an unknown function of the file /print_quiz_records.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273360.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7375

    Last Modified: 9 Aug 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Realtime Quiz System 1.0. This issue affects some unknown processing of the file /my_quiz_result.php. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273359.

    Published: 2 Aug 2024
    6.4
    Medium

    CVE-2024-22278

    Last Modified: 14 Aug 2024

    Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7374

    Last Modified: 9 Aug 2024

    A vulnerability classified as critical was found in SourceCodester Simple Realtime Quiz System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273358 is the identifier assigned to this vulnerability.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7373

    Last Modified: 7 Aug 2024

    A vulnerability classified as critical has been found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=load_answered. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273357 was assigned to this vulnerability.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-33894

    Last Modified: 20 Jun 2025

    Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-38887

    Last Modified: 20 Aug 2024

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-38891

    Last Modified: 24 Feb 2026

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-28297

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 2 Aug 2024
    8.8
    High

    CVE-2024-28298

    Last Modified: 11 Sept 2024

    SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-33892

    Last Modified: 4 Nov 2025

    Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3

    Published: 2 Aug 2024
    6.6
    Medium

    CVE-2024-33895

    Last Modified: 4 Nov 2025

    Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

    Published: 2 Aug 2024
    7.2
    High

    CVE-2024-33896

    Last Modified: 4 Nov 2025

    Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-42459

    Last Modified: 3 Nov 2025

    In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-42460

    Last Modified: 3 Nov 2025

    In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-41310

    Last Modified: 18 Mar 2025

    AndServer 2.1.12 is vulnerable to Directory Traversal.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-38886

    Last Modified: 24 Feb 2026

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.

    Published: 2 Aug 2024
    9.1
    Critical

    CVE-2024-38883

    Last Modified: 13 May 2025

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

    Published: 2 Aug 2024
    7.8
    High

    CVE-2024-38884

    Last Modified: 13 May 2025

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-38885

    Last Modified: 13 May 2025

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.

    Published: 2 Aug 2024
    6.8
    Medium

    CVE-2024-38888

    Last Modified: 13 May 2025

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.

    Published: 2 Aug 2024