CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-41012

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a range in the middle). After the bug has been triggered, use-after-free reads will occur in lock_get_status() when userspace reads /proc/locks. This can likely be used to read arbitrary kernel memory, but can't corrupt kernel memory. Fix it by calling locks_remove_posix() instead, which is designed to reliably get rid of POSIX locks associated with the given file and files_struct and is also used by filp_flush().

    Published: 23 Jul 2024
    9.9
    Critical

    CVE-2024-41110

    Last Modified: 15 Apr 2026

    Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. Using a specially-crafted API request, an Engine API client could make the daemon forward the request or response to an authorization plugin without the body. In certain circumstances, the authorization plugin may allow a request which it would have otherwise denied if the body had been forwarded to it. A security issue was discovered In 2018, where an attacker could bypass AuthZ plugins using a specially crafted API request. This could lead to unauthorized actions, including privilege escalation. Although this issue was fixed in Docker Engine v18.09.1 in January 2019, the fix was not carried forward to later major versions, resulting in a regression. Anyone who depends on authorization plugins that introspect the request and/or response body to make access control decisions is potentially impacted. Docker EE v19.03.x and all versions of Mirantis Container Runtime are not vulnerable. docker-ce v27.1.1 containes patches to fix the vulnerability. Patches have also been merged into the master, 19.03, 20.0, 23.0, 24.0, 25.0, 26.0, and 26.1 release branches. If one is unable to upgrade immediately, avoid using AuthZ plugins and/or restrict access to the Docker API to trusted parties, following the principle of least privilege.

    Published: 23 Jul 2024
    7.5
    High

    CVE-2024-4076

    Last Modified: 15 Apr 2026

    Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.

    Published: 23 Jul 2024
    7.5
    High

    CVE-2024-40060

    Last Modified: 21 Nov 2024

    go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

    Published: 23 Jul 2024
    5.9
    Medium

    CVE-2024-39702

    Last Modified: 24 Sept 2025

    In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of service with relatively few incoming requests. This vulnerability only exists in the OpenResty fork in the openresty/luajit2 GitHub repository. The LuaJIT/LuaJIT repository. is unaffected.

    Published: 23 Jul 2024
    9.8
    Critical

    CVE-2024-41319

    Last Modified: 21 Nov 2024

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

    Published: 23 Jul 2024
    8.8
    High

    CVE-2024-6991

    Last Modified: 7 Aug 2024

    Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Jul 2024
    4.3
    Medium

    CVE-2024-7001

    Last Modified: 19 Mar 2025

    Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 23 Jul 2024
    4.3
    Medium

    CVE-2024-7004

    Last Modified: 29 Oct 2024

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

    Published: 23 Jul 2024
    4.3
    Medium

    CVE-2024-7005

    Last Modified: 7 Aug 2024

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

    Published: 23 Jul 2024
    7.5
    High

    CVE-2024-0760

    Last Modified: 15 Apr 2026

    A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

    Published: 23 Jul 2024
    7.5
    High

    CVE-2024-1975

    Last Modified: 15 Apr 2026

    If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.

    Published: 23 Jul 2024
    7.5
    High

    CVE-2024-1737

    Last Modified: 15 Apr 2026

    Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.

    Published: 23 Jul 2024
    6.5
    Medium

    CVE-2024-1575

    Last Modified: 22 Jan 2025

    The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-6806

    Last Modified: 21 Nov 2024

    The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-6805

    Last Modified: 21 Nov 2024

    The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    9.3
    Critical

    CVE-2024-6913

    Last Modified: 13 Feb 2025

    Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

    Published: 22 Jul 2024
    9.3
    Critical

    CVE-2024-6912

    Last Modified: 13 Feb 2025

    Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-6794

    Last Modified: 21 Nov 2024

    A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-6793

    Last Modified: 21 Nov 2024

    A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6911

    Last Modified: 13 Feb 2025

    Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-6791

    Last Modified: 21 Nov 2024

    A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .vsmodel file. This vulnerability affects VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-6675

    Last Modified: 15 Apr 2026

    A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    5.5
    Medium

    CVE-2024-6638

    Last Modified: 12 Jul 2025

    An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-6121

    Last Modified: 21 Nov 2024

    An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

    Published: 22 Jul 2024
    5.5
    Medium

    CVE-2024-6122

    Last Modified: 21 Nov 2024

    An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-37380

    Last Modified: 15 Apr 2026

    A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later.

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-41130

    Last Modified: 27 Aug 2025

    llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-39688

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to open a new file in the generate_config function, which leads to a limited file write. The issue allows for writing /config/config.json file in arbitrary directory on the server. If a given directory path doesn’t exist, the application will return an error, so this vulnerability could also be used to gain information about existing directories on the server. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39686

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the bert_gen function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39685

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    3.5
    Low

    CVE-2024-41829

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

    Published: 22 Jul 2024
    2.6
    Low

    CVE-2024-41828

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

    Published: 22 Jul 2024
    7.4
    High

    CVE-2024-41827

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

    Published: 22 Jul 2024
    3.5
    Low

    CVE-2024-41826

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

    Published: 22 Jul 2024
    4.6
    Medium

    CVE-2024-41825

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

    Published: 22 Jul 2024
    6.4
    Medium

    CVE-2024-41824

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-41132

    Last Modified: 21 Nov 2024

    ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-41131

    Last Modified: 21 Nov 2024

    ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-29073

    Last Modified: 4 Nov 2025

    An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    9.6
    Critical

    CVE-2024-26020

    Last Modified: 4 Nov 2025

    An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    3.1
    Low

    CVE-2024-32152

    Last Modified: 4 Nov 2025

    A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    7.4
    High

    CVE-2024-32484

    Last Modified: 4 Nov 2025

    An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    4.4
    Medium

    CVE-2024-41129

    Last Modified: 15 Apr 2026

    The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-21552

    Last Modified: 15 Apr 2026

    All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-39902

    Last Modified: 10 Apr 2025

    Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken into account and always considered as unchecked. In situations where the permissions are being restricted some users might still keep, incorrectly, the possibility to edit or manage items. Only change made via the web UI are affected, changes directly made via the REST API are not impacted. This vulnerability is fixed in Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8.

    Published: 22 Jul 2024
    —
    Unknown

    CVE-2024-41807

    Last Modified: 26 Jul 2024

    ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2023-4759. Reason: This record is a reservation duplicate of CVE-2023-4759. Notes: All CVE users should reference CVE-2023-4759 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-39601

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.

    Published: 22 Jul 2024
    9.3
    Critical

    CVE-2024-37998

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled. This could allow an unauthorized attacker to obtain administrative access of the affected applications.

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-38759

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2.

    Published: 22 Jul 2024