CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2024-42381

    Last Modified: 15 Apr 2026

    os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occurs before a user would expect execution of downloaded package content. (237d1e783f7ee261beaba7d3f6bde22da7148b0a was the tested vulnerable version.)

    Published: 31 Jul 2024
    5.1
    Medium

    CVE-2024-7277

    Last Modified: 14 May 2025

    A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/menu.php of the component Add a Menu. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273146 is the identifier assigned to this vulnerability.

    Published: 30 Jul 2024
    5.1
    Medium

    CVE-2024-7276

    Last Modified: 14 May 2025

    A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/member_save.php. The manipulation of the argument last/first leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273145 was assigned to this vulnerability.

    Published: 30 Jul 2024
    5.1
    Medium

    CVE-2024-7275

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273144.

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2024-37281

    Last Modified: 29 Sept 2025

    An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.

    Published: 30 Jul 2024
    5.1
    Medium

    CVE-2024-7274

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issue affects some unknown processing of the file /reservation_status.php. The manipulation of the argument rcode leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273143.

    Published: 30 Jul 2024
    5.3
    Medium

    CVE-2024-7273

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.

    Published: 30 Jul 2024
    6.4
    Medium

    CVE-2024-5901

    Last Modified: 8 Apr 2026

    The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and including, 1.62.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Jul 2024
    3.1
    Low

    CVE-2024-41945

    Last Modified: 15 Apr 2026

    fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions causing some transactions to fail or silently get pruned as they are funded with already used UTXOs. The problem occurs, because the `fund` function in `fuels-ts/packages/account/src/account.ts` gets the needed ressources statelessly with the function `getResourcesToSpend` without taking into consideration already used UTXOs. This issue will lead to unexpected SDK behaviour, such as a transaction not getting included in the `txpool` / in a block or a previous transaction silently getting removed from the `txpool` and replaced with a new one.

    Published: 30 Jul 2024
    7.5
    High

    CVE-2023-33976

    Last Modified: 21 Nov 2024

    TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12.

    Published: 30 Jul 2024
    6.3
    Medium

    CVE-2024-3930

    Last Modified: 21 Nov 2024

    In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

    Published: 30 Jul 2024
    3.5
    Low

    CVE-2024-5250

    Last Modified: 21 Nov 2024

    In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

    Published: 30 Jul 2024
    5.4
    Medium

    CVE-2024-5249

    Last Modified: 9 Jan 2025

    In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

    Published: 30 Jul 2024
    4.6
    Medium

    CVE-2024-41943

    Last Modified: 15 Apr 2026

    I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without any form of validation or sanitation. An attacker can exploit this vulnerability by inserting a payload in the PDF notes that contains malicious code or script. This code will then be executed when the page is loaded in the browser. The vulnerability was fixed in version 5.11.1.

    Published: 30 Jul 2024
    6.8
    Medium

    CVE-2024-41916

    Last Modified: 21 Nov 2024

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.

    Published: 30 Jul 2024
    7.2
    High

    CVE-2024-41915

    Last Modified: 7 Apr 2025

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.

    Published: 30 Jul 2024
    3.7
    Low

    CVE-2022-33167

    Last Modified: 21 Nov 2024

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587.

    Published: 30 Jul 2024
    5.8
    Medium

    CVE-2024-5486

    Last Modified: 21 Nov 2024

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2024-7208

    Last Modified: 15 Apr 2026

    A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain, thus bypass security measures provided by DMARC (or SPF or DKIM) policies.

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2024-7209

    Last Modified: 15 Apr 2026

    A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof the email identify of the sender.

    Published: 30 Jul 2024
    5.5
    Medium

    CVE-2023-26288

    Last Modified: 21 Nov 2024

    IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 248477.

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2023-38001

    Last Modified: 21 Nov 2024

    IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260206.

    Published: 30 Jul 2024
    5.4
    Medium

    CVE-2023-26289

    Last Modified: 21 Nov 2024

    IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 248478.

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2024-41944

    Last Modified: 15 Apr 2026

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `sortBy` parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.

    Published: 30 Jul 2024
    8.8
    High

    CVE-2024-7297

    Last Modified: 27 Mar 2026

    Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

    Published: 30 Jul 2024
    6.5
    Medium

    CVE-2024-41804

    Last Modified: 21 Nov 2024

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the `formula` parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.

    Published: 30 Jul 2024
    8.1
    High

    CVE-2024-41802

    Last Modified: 21 Nov 2024

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the APIs for importing JSON and importing a Layout containing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue

    Published: 30 Jul 2024
    4.9
    Medium

    CVE-2024-41803

    Last Modified: 21 Nov 2024

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.

    Published: 30 Jul 2024
    —
    Unknown

    CVE-2024-7298

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Jul 2024
    6.3
    Medium

    CVE-2024-41109

    Last Modified: 4 Nov 2025

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore installation, PHP version, MYSQL version, installed bundles and all database tables and their row count in the system. This vulnerability is fixed in 1.5.2, 1.4.6, and 1.3.10.

    Published: 30 Jul 2024
    7.1
    High

    CVE-2024-4188

    Last Modified: 15 Apr 2026

    Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

    Published: 30 Jul 2024
    6.1
    Medium

    CVE-2024-39320

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

    Published: 30 Jul 2024
    4.9
    Medium

    CVE-2024-37299

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

    Published: 30 Jul 2024
    6.3
    Medium

    CVE-2024-37165

    Last Modified: 21 Nov 2024

    Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. This vulnerability is fixed in 3.2.3 and 3.3.0.beta3.

    Published: 30 Jul 2024
    9.3
    Critical

    CVE-2024-6699

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection. This issue affects Mikafon MA7: from v3.0 before v3.1.

    Published: 30 Jul 2024
    7.2
    High

    CVE-2024-7127

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the username during registration, it can be executed later in the application panel. This could lead to the unauthorised acquisition of information (e.g. cookies from a logged-in user). After multiple attempts to contact the vendor we did not receive any answer. Our team has confirmed the existence of this vulnerability. We suppose this issue affects Social Marketing Tool in all versions.

    Published: 30 Jul 2024
    9.8
    Critical

    CVE-2024-41702

    Last Modified: 21 Nov 2024

    SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    Published: 30 Jul 2024
    5.3
    Medium

    CVE-2024-41701

    Last Modified: 15 Apr 2026

    AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    Published: 30 Jul 2024
    7.5
    High

    CVE-2024-41696

    Last Modified: 15 Apr 2026

    Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    Published: 30 Jul 2024
    7.5
    High

    CVE-2024-41695

    Last Modified: 15 Apr 2026

    Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

    Published: 30 Jul 2024
    5.3
    Medium

    CVE-2024-41694

    Last Modified: 15 Apr 2026

    Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    Published: 30 Jul 2024
    6.9
    Medium

    CVE-2024-7226

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user of the component Password Change Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272806 is the identifier assigned to this vulnerability.

    Published: 30 Jul 2024
    5.5
    Medium

    CVE-2024-38432

    Last Modified: 21 Nov 2024

    Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

    Published: 30 Jul 2024
    5.3
    Medium

    CVE-2024-38431

    Last Modified: 21 Nov 2024

    Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

    Published: 30 Jul 2024
    5.4
    Medium

    CVE-2024-38430

    Last Modified: 21 Nov 2024

    Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 30 Jul 2024
    7.2
    High

    CVE-2024-41924

    Last Modified: 15 Apr 2026

    Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some known vulnerabilities.

    Published: 30 Jul 2024
    6.1
    Medium

    CVE-2024-41141

    Last Modified: 15 Apr 2026

    Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page.

    Published: 30 Jul 2024
    7.5
    High

    CVE-2024-38429

    Last Modified: 21 Nov 2024

    Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

    Published: 30 Jul 2024
    6.4
    Medium

    CVE-2024-40895

    Last Modified: 15 Apr 2026

    FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.

    Published: 30 Jul 2024
    5.3
    Medium

    CVE-2024-7225

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy of the component Edit Insurance Policy Page. The manipulation of the argument pname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272805 was assigned to this vulnerability.

    Published: 30 Jul 2024