CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2024-7007

    Last Modified: 21 Nov 2024

    Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

    Published: 25 Jul 2024
    4.8
    Medium

    CVE-2024-41800

    Last Modified: 21 Nov 2024

    Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.

    Published: 25 Jul 2024
    6.9
    Medium

    CVE-2024-7101

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272423. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Jul 2024
    5.3
    Medium

    CVE-2024-41806

    Last Modified: 15 Apr 2026

    The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become publicly available when the uploader uses versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper. The patch in commit cb729a3ced0404736dfa0ae768526c82b608657b ensures that cohorts data uploaded to AWS S3 buckets is written with a private ACL. Beyond patching, deployers should also ensure that existing cohorts uploads have a private ACL, or that other precautions are taken to avoid public access.

    Published: 25 Jul 2024
    6.3
    Medium

    CVE-2024-36111

    Last Modified: 15 Apr 2026

    KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The JWT key in the default configuration file is empty. Although a random 32-bit string will be generated to overwrite the key in the configuration file when the key is detected to be empty in the configuration file reading logic, the key is empty during actual verification. Using an empty key to generate a JWT token can bypass the login verification and directly take over the back end. Version 1.8.0 contains a patch for this issue.

    Published: 25 Jul 2024
    8.4
    High

    CVE-2024-39672

    Last Modified: 21 Nov 2024

    Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

    Published: 25 Jul 2024
    9.3
    Critical

    CVE-2024-39671

    Last Modified: 21 Nov 2024

    Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 25 Jul 2024
    5.5
    Medium

    CVE-2023-7271

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 25 Jul 2024
    6.2
    Medium

    CVE-2024-39670

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 25 Jul 2024
    6.2
    Medium

    CVE-2024-39674

    Last Modified: 21 Nov 2024

    Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 25 Jul 2024
    6.8
    Medium

    CVE-2024-39673

    Last Modified: 18 Sept 2025

    Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 25 Jul 2024
    8.8
    High

    CVE-2024-6589

    Last Modified: 8 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 25 Jul 2024
    9.8
    Critical

    CVE-2024-37084

    Last Modified: 21 Nov 2024

    In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

    Published: 25 Jul 2024
    7.7
    High

    CVE-2024-3056

    Last Modified: 14 Nov 2025

    A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is out-of-memory (OOM) killed. While the malicious container's cgroup will be removed, the IPC resources it created are not. Those resources are tied to the IPC namespace that will not be removed until all containers using it are stopped, and one non-malicious container is holding the namespace open. The malicious container is restarted, either automatically or by attacker control, repeating the process and increasing the amount of memory consumed. With a container configured to restart always, such as `podman run --restart=always`, this can result in a memory-based denial of service of the system.

    Published: 25 Jul 2024
    6.5
    Medium

    CVE-2024-6972

    Last Modified: 2 Jul 2025

    In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

    Published: 25 Jul 2024
    2.2
    Low

    CVE-2024-4811

    Last Modified: 2 Jul 2025

    In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

    Published: 25 Jul 2024
    4.3
    Medium

    CVE-2024-7057

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

    Published: 25 Jul 2024
    7.7
    High

    CVE-2024-7047

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

    Published: 25 Jul 2024
    6.4
    Medium

    CVE-2024-8105

    Last Modified: 28 Jun 2026

    A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

    Published: 25 Jul 2024
    8.8
    High

    CVE-2024-36542

    Last Modified: 15 Apr 2026

    Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

    Published: 25 Jul 2024
    7.2
    High

    CVE-2024-40318

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 25 Jul 2024
    4.8
    Medium

    CVE-2024-41707

    Last Modified: 18 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.

    Published: 25 Jul 2024
    7.5
    High

    CVE-2023-38522

    Last Modified: 3 Nov 2025

    Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

    Published: 25 Jul 2024
    7.5
    High

    CVE-2024-35161

    Last Modified: 3 Nov 2025

    Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users can set a new setting (proxy.config.http.drop_chunked_trailers) not to forward chunked trailer section. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

    Published: 25 Jul 2024
    9.8
    Critical

    CVE-2024-38287

    Last Modified: 21 Nov 2024

    The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.

    Published: 25 Jul 2024
    7.2
    High

    CVE-2024-38288

    Last Modified: 21 Nov 2024

    A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

    Published: 25 Jul 2024
    9.8
    Critical

    CVE-2024-38289

    Last Modified: 21 Nov 2024

    A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

    Published: 25 Jul 2024
    5.4
    Medium

    CVE-2024-40324

    Last Modified: 21 Nov 2024

    A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

    Published: 25 Jul 2024
    9.8
    Critical

    CVE-2024-41468

    Last Modified: 21 Nov 2024

    Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

    Published: 25 Jul 2024
    9.8
    Critical

    CVE-2024-41473

    Last Modified: 21 Nov 2024

    Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac

    Published: 25 Jul 2024
    7.1
    High

    CVE-2024-41705

    Last Modified: 21 Nov 2024

    A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14.P4 (6.14.0.4) and 6.13 P4 (6.13.0.4) are also fixed releases. This vulnerability is similar to, but not identical to, CVE-2023-30639.

    Published: 25 Jul 2024
    7.3
    High

    CVE-2024-41706

    Last Modified: 21 Nov 2024

    A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P4 (6.14.0.4) is also a fixed release.

    Published: 25 Jul 2024
    4.4
    Medium

    CVE-2024-5067

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

    Published: 24 Jul 2024
    2.6
    Low

    CVE-2024-7060

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

    Published: 24 Jul 2024
    4.1
    Medium

    CVE-2024-7091

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

    Published: 24 Jul 2024
    5.3
    Medium

    CVE-2024-7081

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file expcatadd.php. The manipulation of the argument id/title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Jul 2024
    6.8
    Medium

    CVE-2024-41136

    Last Modified: 21 Nov 2024

    An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 24 Jul 2024
    7.2
    High

    CVE-2024-41135

    Last Modified: 15 Apr 2026

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

    Published: 24 Jul 2024
    7.2
    High

    CVE-2024-41134

    Last Modified: 15 Apr 2026

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

    Published: 24 Jul 2024
    7.2
    High

    CVE-2024-41133

    Last Modified: 15 Apr 2026

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

    Published: 24 Jul 2024
    6.9
    Medium

    CVE-2024-7080

    Last Modified: 22 Apr 2025

    A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /E-Insurance/. The manipulation leads to direct request. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272365 was assigned to this vulnerability.

    Published: 24 Jul 2024
    6.3
    Medium

    CVE-2024-1724

    Last Modified: 21 Nov 2024

    In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

    Published: 24 Jul 2024
    7.2
    High

    CVE-2024-33519

    Last Modified: 15 Apr 2026

    A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

    Published: 24 Jul 2024
    2.7
    Low

    CVE-2024-0231

    Last Modified: 21 Nov 2024

    A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

    Published: 24 Jul 2024
    4.3
    Medium

    CVE-2024-21684

    Last Modified: 30 Jul 2025

    There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, allows an unauthenticated attacker to redirect a victim user upon login to Bitbucket Data Center to any arbitrary site which can be utilized for further exploitation which has low impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Bitbucket Data Center customers upgrade to the version. If you are unable to do so, upgrade your instance to one of the supported fixed versions.

    Published: 24 Jul 2024
    7.5
    High

    CVE-2024-41672

    Last Modified: 21 Nov 2024

    DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false`. This vulnerability provides an attacker with access to filesystem even when access is expected to be disabled and other similar functions do NOT provide access. There seem to be two vectors to this vulnerability. First, access to files that should otherwise not be allowed. Second, the content from a file can be read (e.g. `/etc/hosts`, `proc/self/environ`, etc) even though that doesn't seem to be the intent of the sniff_csv function. A fix for this issue is available in commit c9b7c98aa0e1cd7363fe8bb8543a95f38e980d8a and is expected to be part of version 1.1.0.

    Published: 24 Jul 2024
    8.8
    High

    CVE-2024-41667

    Last Modified: 15 Apr 2026

    OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL for handling login to override the default OpenAM login, they did not restrict the `CustomLoginUrlTemplate`, allowing it to be set freely. Commit fcb8432aa77d5b2e147624fe954cb150c568e0b8 introduces `TemplateClassResolver.SAFER_RESOLVER` to disable the resolution of commonly exploited classes in FreeMarker template injection. As of time of publication, this fix is expected to be part of version 15.0.4.

    Published: 24 Jul 2024
    2.4
    Low

    CVE-2024-37533

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.

    Published: 24 Jul 2024
    8.8
    High

    CVE-2024-41091

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tun_xdp_one-->eth_type_trans() may access the Ethernet header although it can be less than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tun_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted for IFF_TAP. This is to drop any frame shorter than the Ethernet header size just like how tun_get_user() does. CVE: CVE-2024-41091

    Published: 24 Jul 2024
    8.8
    High

    CVE-2024-41090

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tap_get_user_xdp()-->skb_set_network_header() may assume the size is more than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tap_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted. This is to drop any frame shorter than the Ethernet header size just like how tap_get_user() does. CVE: CVE-2024-41090

    Published: 24 Jul 2024