CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-6791

    Last Modified: 21 Nov 2024

    A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .vsmodel file. This vulnerability affects VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-6675

    Last Modified: 15 Apr 2026

    A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects VeriStand 2024 Q2 and prior versions.

    Published: 22 Jul 2024
    5.5
    Medium

    CVE-2024-6638

    Last Modified: 12 Jul 2025

    An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-6121

    Last Modified: 21 Nov 2024

    An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

    Published: 22 Jul 2024
    5.5
    Medium

    CVE-2024-6122

    Last Modified: 21 Nov 2024

    An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-37380

    Last Modified: 15 Apr 2026

    A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later.

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-41130

    Last Modified: 27 Aug 2025

    llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-39688

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to open a new file in the generate_config function, which leads to a limited file write. The issue allows for writing /config/config.json file in arbitrary directory on the server. If a given directory path doesn’t exist, the application will return an error, so this vulnerability could also be used to gain information about existing directories on the server. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39686

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the bert_gen function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39685

    Last Modified: 21 Nov 2024

    Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

    Published: 22 Jul 2024
    3.5
    Low

    CVE-2024-41829

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

    Published: 22 Jul 2024
    2.6
    Low

    CVE-2024-41828

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

    Published: 22 Jul 2024
    7.4
    High

    CVE-2024-41827

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

    Published: 22 Jul 2024
    3.5
    Low

    CVE-2024-41826

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

    Published: 22 Jul 2024
    4.6
    Medium

    CVE-2024-41825

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

    Published: 22 Jul 2024
    6.4
    Medium

    CVE-2024-41824

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-41132

    Last Modified: 21 Nov 2024

    ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-41131

    Last Modified: 21 Nov 2024

    ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-29073

    Last Modified: 4 Nov 2025

    An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    9.6
    Critical

    CVE-2024-26020

    Last Modified: 4 Nov 2025

    An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    3.1
    Low

    CVE-2024-32152

    Last Modified: 4 Nov 2025

    A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    7.4
    High

    CVE-2024-32484

    Last Modified: 4 Nov 2025

    An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A specially crafted flashcard can lead to JavaScript code execution and result in an arbitrary file read. An attacker can share a malicious flashcard to trigger this vulnerability.

    Published: 22 Jul 2024
    4.4
    Medium

    CVE-2024-41129

    Last Modified: 15 Apr 2026

    The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing `subprocess.CalledProcessError`. This vulnerability is fixed in 2.15.0.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-21552

    Last Modified: 15 Apr 2026

    All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-39902

    Last Modified: 10 Apr 2025

    Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken into account and always considered as unchecked. In situations where the permissions are being restricted some users might still keep, incorrectly, the possibility to edit or manage items. Only change made via the web UI are affected, changes directly made via the REST API are not impacted. This vulnerability is fixed in Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8.

    Published: 22 Jul 2024
    —
    Unknown

    CVE-2024-41807

    Last Modified: 26 Jul 2024

    ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2023-4759. Reason: This record is a reservation duplicate of CVE-2023-4759. Notes: All CVE users should reference CVE-2023-4759 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-39601

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.

    Published: 22 Jul 2024
    9.3
    Critical

    CVE-2024-37998

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled. This could allow an unauthorized attacker to obtain administrative access of the affected applications.

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-38759

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2.

    Published: 22 Jul 2024
    7.2
    High

    CVE-2024-37942

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5.

    Published: 22 Jul 2024
    6.4
    Medium

    CVE-2024-38723

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.

    Published: 22 Jul 2024
    7.2
    High

    CVE-2024-38728

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

    Published: 22 Jul 2024
    4.9
    Medium

    CVE-2024-38730

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.

    Published: 22 Jul 2024
    4.3
    Medium

    CVE-2024-38701

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

    Published: 22 Jul 2024
    7.6
    High

    CVE-2024-38692

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11.

    Published: 22 Jul 2024
    8.5
    High

    CVE-2024-38708

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.6.1.

    Published: 22 Jul 2024
    8.5
    High

    CVE-2024-38755

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.

    Published: 22 Jul 2024
    9.3
    Critical

    CVE-2024-38773

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.

    Published: 22 Jul 2024
    7.6
    High

    CVE-2024-38788

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bởi Admin 2020 UiPress lite allows SQL Injection.This issue affects UiPress lite: from n/a through 3.4.06.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-33933

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor – Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor – Header, Footer & Blocks Template: from n/a through 1.6.35.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-35656

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-37097

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UnitedThemes Shortcodes by United Themes allows Reflected XSS.This issue affects Shortcodes by United Themes: from n/a before 5.0.5.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37100

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37101

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AF themes WP Post Author allows Stored XSS.This issue affects WP Post Author: from n/a through 3.6.7.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-6542

    Last Modified: 21 Nov 2024

    Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-34457

    Last Modified: 21 Nov 2024

    On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-38503

    Last Modified: 6 Dec 2024

    When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37114

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites my-favorites allows DOM-Based XSS.This issue affects My Favorites: from n/a through <= 1.4.3.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37116

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-37117

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3.

    Published: 22 Jul 2024