CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-6198

    Last Modified: 13 Aug 2024

    A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

    Published: 31 Jul 2024
    7.3
    High

    CVE-2022-4001

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

    Published: 31 Jul 2024
    7.2
    High

    CVE-2022-4002

    Last Modified: 13 Aug 2024

    A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

    Published: 31 Jul 2024
    2.7
    Low

    CVE-2022-4003

    Last Modified: 13 Aug 2024

    A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

    Published: 31 Jul 2024
    7.8
    High

    CVE-2023-1577

    Last Modified: 13 Aug 2024

    A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.

    Published: 31 Jul 2024
    2.1
    Low

    CVE-2024-4187

    Last Modified: 15 Aug 2024

    Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

    Published: 31 Jul 2024
    9.8
    Critical

    CVE-2024-41660

    Last Modified: 15 Apr 2026

    slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.

    Published: 31 Jul 2024
    8.5
    High

    CVE-2024-7325

    Last Modified: 11 Sept 2024

    A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the library VCL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The identifier of this vulnerability is VDB-273248. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    4.4
    Medium

    CVE-2024-41951

    Last Modified: 15 Apr 2026

    Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding languages are visible in code. The Problem was patched in 0.2.4.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-41954

    Last Modified: 5 Sept 2024

    FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could create new accounts for the web application and much more. The vulnerability is fixed in 1.5.10.41.

    Published: 31 Jul 2024
    5.2
    Medium

    CVE-2024-41955

    Last Modified: 15 Aug 2024

    Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-41108

    Last Modified: 5 Sept 2024

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to obtain the configuration information. This data can only be retrieved if a task is pending on that host. Otherwise, an error message containing "Invalid tasking!" will be returned. The domainpassword in the hostinfo dump is hidden even to authenticated users, as it is displayed as a row of asterisks when navigating to the host's Active Directory settings. This vulnerability is fixed in 1.5.10.41.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-40645

    Last Modified: 5 Sept 2024

    FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner image requiring it to be 650 pixels wide and 120 pixels high. Apart from that, there are no checks on things like file extensions. This can be abused by appending a PHP webshell to the end of the image and changing the extension to anything the PHP web server will parse. This vulnerability is fixed in 1.5.10.41.

    Published: 31 Jul 2024
    8.5
    High

    CVE-2024-7324

    Last Modified: 15 Apr 2026

    A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the component BPL Handler. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The associated identifier of this vulnerability is VDB-273247. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    4.9
    Medium

    CVE-2024-23444

    Last Modified: 4 Apr 2025

    It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.

    Published: 31 Jul 2024
    5.6
    Medium

    CVE-2024-6978

    Last Modified: 27 Aug 2024

    Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-6977

    Last Modified: 27 Aug 2024

    A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-6975

    Last Modified: 27 Aug 2024

    Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-6974

    Last Modified: 27 Aug 2024

    Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-6973

    Last Modified: 27 Aug 2024

    Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

    Published: 31 Jul 2024
    4.3
    Medium

    CVE-2024-41953

    Last Modified: 8 Jan 2025

    Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be entered by users or administrators. Due to a missing output sanitization, these emails could include malicious code. This may potentially lead to a threat where an attacker, without privileges, could send out altered notifications that are part of the registration processes. An attacker could create a malicious link, where the injected code would be rendered as part of the email. On the user's detail page, the username was also not sanitized and would also render HTML, giving an attacker the same vulnerability. While it was possible to inject HTML including javascript, the execution of such scripts would be prevented by most email clients and the Content Security Policy in Console UI. This vulnerability is fixed in 2.58.1, 2.57.1, 2.56.2, 2.55.5, 2.54.8 2.53.9, and 2.52.3.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-41952

    Last Modified: 8 Jan 2025

    Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't exist and report "Username or Password invalid". Due to a implementation change to prevent deadlocks calling the database, the flag would not be correctly respected in all cases and an attacker would gain information if an account exist within ZITADEL, since the error message shows "object not found" instead of the generic error message. This vulnerability is fixed in 2.58.1, 2.57.1, 2.56.2, 2.55.5, 2.54.8, and 2.53.9.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-41950

    Last Modified: 15 Apr 2026

    Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code. The vulnerability has been fixed with Haystack `2.3.1`.

    Published: 31 Jul 2024
    4.7
    Medium

    CVE-2024-39694

    Last Modified: 15 Apr 2026

    Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party, untrusted site. Note: by itself, this vulnerability does **not** allow an attacker to obtain user credentials, authorization codes, access tokens, refresh tokens, or identity tokens. An attacker could however exploit this vulnerability as part of a phishing attack designed to steal user credentials. This vulnerability is fixed in 7.0.6, 6.3.10, 6.2.5, 6.1.8, and 6.0.5. Duende.IdentityServer 5.1 and earlier and all versions of IdentityServer4 are no longer supported and will not be receiving updates. If upgrading is not possible, use `IUrlHelper.IsLocalUrl` from ASP.NET Core to validate return Urls in user interface code in the IdentityServer host.

    Published: 31 Jul 2024
    5.4
    Medium

    CVE-2024-39318

    Last Modified: 15 Apr 2026

    The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have the required permission. It is not persistent, i.e. the payload is only executed during the upload. In effect, an attacker will have to trick an editor/administrator into uploading a strangely named file.

    Published: 31 Jul 2024
    9
    Critical

    CVE-2024-41947

    Last Modified: 6 Sept 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.8 and 16.3.0RC1.

    Published: 31 Jul 2024
    9.9
    Critical

    CVE-2024-37901

    Last Modified: 6 Sept 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to their user profile or any other page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.21, 15.5.5 and 15.10.2.

    Published: 31 Jul 2024
    6.4
    Medium

    CVE-2024-37900

    Last Modified: 10 Jan 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a malicious name. The malicious code is solely executed during the upload and affects only the user uploading the attachment. While this allows performing actions in the name of that user, it seems unlikely that a user wouldn't notice the malicious filename while uploading the attachment. This has been patched in XWiki 14.10.21, 15.5.5, 15.10.6 and 16.0.0.

    Published: 31 Jul 2024
    4.3
    Medium

    CVE-2024-37898

    Last Modified: 6 Sept 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous version of the page is moved into the recycle bin and can be restored from there by an admin. As the user is recorded as deleter, the user would in theory also be able to view the deleted content, but this is not directly possible as rights of the previous version are transferred to the new page and thus the user still doesn't have view right on the page. It therefore doesn't seem to be possible to exploit this to gain any rights. This has been patched in XWiki 14.10.21, 15.5.5 and 15.10.6 by cancelling save operations by users when a new document shall be saved despite the document's existing already.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-7340

    Last Modified: 15 Apr 2026

    The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

    Published: 31 Jul 2024
    3.3
    Low

    CVE-2024-37135

    Last Modified: 22 Nov 2024

    DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

    Published: 31 Jul 2024
    3.3
    Low

    CVE-2024-31203

    Last Modified: 30 Sept 2024

    A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.

    Published: 31 Jul 2024
    7.8
    High

    CVE-2024-31202

    Last Modified: 30 Sept 2024

    A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-31201

    Last Modified: 12 Aug 2024

    A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.

    Published: 31 Jul 2024
    4.2
    Medium

    CVE-2024-31200

    Last Modified: 12 Aug 2024

    A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-31199

    Last Modified: 30 Sept 2024

    A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

    Published: 31 Jul 2024
    8.3
    High

    CVE-2024-3083

    Last Modified: 30 Sept 2024

    A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.

    Published: 31 Jul 2024
    4.2
    Medium

    CVE-2024-3082

    Last Modified: 30 Sept 2024

    A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.

    Published: 31 Jul 2024
    5.5
    Medium

    CVE-2024-39379

    Last Modified: 16 Oct 2024

    Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 31 Jul 2024
    6.4
    Medium

    CVE-2024-6208

    Last Modified: 8 Apr 2026

    The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7321

    Last Modified: 12 Aug 2024

    A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7320

    Last Modified: 12 Aug 2024

    A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php of the component Admin Login. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273231.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-7135

    Last Modified: 8 Apr 2026

    The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 31 Jul 2024
    4.9
    Medium

    CVE-2024-6725

    Last Modified: 8 Apr 2026

    The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7311

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273203.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7310

    Last Modified: 13 Aug 2024

    A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. The manipulation of the argument sort leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273202 is the identifier assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7309

    Last Modified: 13 Aug 2024

    A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. The manipulation of the argument school leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273201 was assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7308

    Last Modified: 13 Aug 2024

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_bill.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273200.

    Published: 31 Jul 2024
    6.7
    Medium

    CVE-2024-37129

    Last Modified: 24 Jul 2026

    Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.

    Published: 31 Jul 2024
    7.3
    High

    CVE-2024-32857

    Last Modified: 8 Aug 2024

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

    Published: 31 Jul 2024