CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-39827

    Last Modified: 5 Aug 2025

    Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.

    Published: 15 Jul 2024
    6.8
    Medium

    CVE-2024-39826

    Last Modified: 2 Oct 2025

    Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.

    Published: 15 Jul 2024
    7.1
    High

    CVE-2024-27238

    Last Modified: 5 Aug 2025

    Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-27241

    Last Modified: 20 Aug 2025

    Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

    Published: 15 Jul 2024
    7.1
    High

    CVE-2024-27240

    Last Modified: 5 Aug 2025

    Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.

    Published: 15 Jul 2024
    —
    Unknown

    CVE-2024-6761

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Jul 2024
    5.1
    Medium

    CVE-2024-38496

    Last Modified: 15 Apr 2026

    The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-38495

    Last Modified: 15 Apr 2026

    A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.

    Published: 15 Jul 2024
    8.6
    High

    CVE-2024-38494

    Last Modified: 15 Apr 2026

    This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

    Published: 15 Jul 2024
    6.8
    Medium

    CVE-2024-38493

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on a specially crafted link to the PAM UI web interface could potentially execute arbitrary client-side code in the context of PAM UI.

    Published: 15 Jul 2024
    9.4
    Critical

    CVE-2024-38492

    Last Modified: 15 Apr 2026

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

    Published: 15 Jul 2024
    8.4
    High

    CVE-2024-38491

    Last Modified: 15 Apr 2026

    The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.

    Published: 15 Jul 2024
    5.1
    Medium

    CVE-2024-36458

    Last Modified: 15 Apr 2026

    The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-36457

    Last Modified: 15 Apr 2026

    The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

    Published: 15 Jul 2024
    9.4
    Critical

    CVE-2024-36456

    Last Modified: 15 Apr 2026

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

    Published: 15 Jul 2024
    9.4
    Critical

    CVE-2024-36455

    Last Modified: 15 Apr 2026

    An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

    Published: 15 Jul 2024
    7.8
    High

    CVE-2024-6689

    Last Modified: 15 Apr 2026

    Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-6746

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js of the component HTTP GET Request Handler. The manipulation with the input /../../../../../../../../../Windows/win.ini leads to path traversal: '../filedir'. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier VDB-271477 was assigned to this vulnerability. NOTE: The code maintainer explains, that this is not a big issue "because the default is that the software runs locally without going through the Internet".

    Published: 15 Jul 2024
    6.2
    Medium

    CVE-2024-5402

    Last Modified: 21 Nov 2024

    Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868.

    Published: 15 Jul 2024
    6.9
    Medium

    CVE-2024-6745

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown function of the file adminauthenticate.php of the component Login. The manipulation of the argument email/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271476.

    Published: 15 Jul 2024
    4.3
    Medium

    CVE-2024-6398

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.

    Published: 15 Jul 2024
    4.2
    Medium

    CVE-2024-39767

    Last Modified: 21 Nov 2024

    Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

    Published: 15 Jul 2024
    2.6
    Low

    CVE-2024-32945

    Last Modified: 21 Nov 2024

    Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

    Published: 15 Jul 2024
    5.8
    Medium

    CVE-2024-6741

    Last Modified: 21 Nov 2024

    Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6740

    Last Modified: 21 Nov 2024

    Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.

    Published: 15 Jul 2024
    8.8
    High

    CVE-2023-49566

    Last Modified: 27 Mar 2025

    In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSource Manager Module will result in jndi injection. Therefore, the parameters in the DB2 URL should be blacklisted.  This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out. Versions of Apache Linkis <=1.5.0 will be affected. We recommend users upgrade the version of Linkis to version 1.6.0.

    Published: 15 Jul 2024
    8.8
    High

    CVE-2023-46801

    Last Modified: 21 Nov 2024

    In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the server and execute them. This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out.  We recommend that users upgrade the java version to >= 1.8.0_241. Or users upgrade Linkis to version 1.6.0.

    Published: 15 Jul 2024
    6.5
    Medium

    CVE-2023-41916

    Last Modified: 14 Mar 2025

    In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. This attack requires the attacker to obtain an authorized account from Linkis before it can be carried out. Versions of Apache Linkis = 1.4.0 will be affected.  We recommend users upgrade the version of Linkis to version 1.5.0.

    Published: 15 Jul 2024
    5.2
    Medium

    CVE-2024-23794

    Last Modified: 21 Nov 2024

    An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting 'RequiredLock' of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' in the system configuration.This issue affects OTRS:  * 8.0.X * 2023.X * from 2024.X through 2024.4.x

    Published: 15 Jul 2024
    5.7
    Medium

    CVE-2024-6540

    Last Modified: 21 Nov 2024

    Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator. This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

    Published: 15 Jul 2024
    9.8
    Critical

    CVE-2024-6744

    Last Modified: 21 Nov 2024

    The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.

    Published: 15 Jul 2024
    9.8
    Critical

    CVE-2024-6743

    Last Modified: 21 Nov 2024

    AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6289

    Last Modified: 27 Aug 2025

    The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6076

    Last Modified: 21 Nov 2024

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 15 Jul 2024
    8.8
    High

    CVE-2024-6075

    Last Modified: 21 Nov 2024

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6074

    Last Modified: 21 Nov 2024

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6073

    Last Modified: 21 Nov 2024

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 15 Jul 2024
    6.1
    Medium

    CVE-2024-6072

    Last Modified: 21 Nov 2024

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 15 Jul 2024
    8.8
    High

    CVE-2024-5630

    Last Modified: 21 Nov 2024

    The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

    Published: 15 Jul 2024
    5.4
    Medium

    CVE-2024-6742

    Last Modified: 21 Nov 2024

    AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regular privileges to inject JavaScript and perform Reflected Cross-site scripting attacks.

    Published: 15 Jul 2024
    8.5
    High

    CVE-2024-21513

    Last Modified: 21 Nov 2024

    Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from the database, the code will attempt to call 'eval' on all values. An attacker can exploit this vulnerability and execute arbitrary python code if they can control the input prompt and the server is configured with VectorSQLDatabaseChain. **Notes:** Impact on the Confidentiality, Integrity and Availability of the vulnerable component: Confidentiality: Code execution happens within the impacted component, in this case langchain-experimental, so all resources are necessarily accessible. Integrity: There is nothing protected by the impacted component inherently. Although anything returned from the component counts as 'information' for which the trustworthiness can be compromised. Availability: The loss of availability isn't caused by the attack itself, but it happens as a result during the attacker's post-exploitation steps. Impact on the Confidentiality, Integrity and Availability of the subsequent system: As a legitimate low-privileged user of the package (PR:L) the attacker does not have more access to data owned by the package as a result of this vulnerability than they did with normal usage (e.g. can query the DB). The unintended action that one can perform by breaking out of the app environment and exfiltrating files, making remote connections etc. happens during the post exploitation phase in the subsequent system - in this case, the OS. AT:P: An attacker needs to be able to influence the input prompt, whilst the server is configured with the VectorSQLDatabaseChain plugin.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-6739

    Last Modified: 21 Nov 2024

    The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

    Published: 15 Jul 2024
    5.3
    Medium

    CVE-2024-6738

    Last Modified: 21 Nov 2024

    The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.

    Published: 15 Jul 2024
    8.8
    High

    CVE-2024-6737

    Last Modified: 21 Nov 2024

    The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account.

    Published: 15 Jul 2024
    4.3
    Medium

    CVE-2024-39740

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could allow an attacker to gather information for future attacks against the system. IBM X-Force ID: 296009.

    Published: 15 Jul 2024
    4.3
    Medium

    CVE-2024-39741

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 296010.

    Published: 15 Jul 2024
    4.3
    Medium

    CVE-2024-39729

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive information from source code that could be used in further attacks against the system. IBM X-Force ID: 295968.

    Published: 15 Jul 2024
    5.4
    Medium

    CVE-2024-39735

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 296002.

    Published: 15 Jul 2024
    5.9
    Medium

    CVE-2024-39731

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 295970.

    Published: 15 Jul 2024
    6.4
    Medium

    CVE-2024-39728

    Last Modified: 21 Nov 2024

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 295967.

    Published: 15 Jul 2024