CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2024-3596

    Last Modified: 12 May 2026

    RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

    Published: 9 Jul 2024
    6.3
    Medium

    CVE-2024-6600

    Last Modified: 30 Oct 2025

    Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

    Published: 9 Jul 2024
    4.7
    Medium

    CVE-2024-6601

    Last Modified: 30 Oct 2025

    A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

    Published: 9 Jul 2024
    7.4
    High

    CVE-2024-6603

    Last Modified: 30 Oct 2025

    In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2024-35264

    Last Modified: 10 Feb 2026

    .NET and Visual Studio Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-37829

    Last Modified: 10 Oct 2025

    An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2023-50805

    Last Modified: 14 Jul 2025

    A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

    Published: 9 Jul 2024
    6.7
    Medium

    CVE-2024-27386

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-38095

    Last Modified: 9 Dec 2025

    .NET and Visual Studio Denial of Service Vulnerability

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-39072

    Last Modified: 17 Oct 2025

    AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-37870

    Last Modified: 15 Dec 2025

    SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-38963

    Last Modified: 31 Dec 2025

    Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-39071

    Last Modified: 15 Apr 2026

    Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.

    Published: 9 Jul 2024
    6.5
    Medium

    CVE-2024-22020

    Last Modified: 15 Apr 2026

    A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports. Exploiting this flaw can violate network import security, posing a risk to developers and servers.

    Published: 9 Jul 2024
    6
    Medium

    CVE-2024-27363

    Last Modified: 15 Apr 2026

    A vulnerability was discovered in Samsung Mobile Processor Exynos 850, Exynos 9610, Exynos 980, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, and Exynos W930 where it does not properly check a pointer address, which can lead to a Information disclosure.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-38517

    Last Modified: 15 Apr 2026

    Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-28882

    Last Modified: 10 Jun 2025

    OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

    Published: 8 Jul 2024
    5.3
    Medium

    CVE-2024-3653

    Last Modified: 15 Apr 2026

    A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.

    Published: 8 Jul 2024
    7.5
    High

    CVE-2024-5971

    Last Modified: 15 Apr 2026

    A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.

    Published: 8 Jul 2024
    2
    Low

    CVE-2024-38372

    Last Modified: 15 Apr 2026

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.

    Published: 8 Jul 2024
    7.5
    High

    CVE-2024-6227

    Last Modified: 21 Nov 2024

    A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections.

    Published: 8 Jul 2024
    2.3
    Low

    CVE-2024-6580

    Last Modified: 26 Sept 2025

    The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.

    Published: 8 Jul 2024
    7
    High

    CVE-2024-6409

    Last Modified: 15 Apr 2026

    A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.

    Published: 8 Jul 2024
    5.3
    Medium

    CVE-2024-4882

    Last Modified: 15 Apr 2026

    The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.

    Published: 8 Jul 2024
    7.5
    High

    CVE-2024-39896

    Last Modified: 3 Jan 2025

    Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an email address exists in Directus and belongs to a known SSO provider then it will throw a "helpful" error that the user belongs to another provider. This vulnerability is fixed in 10.13.0.

    Published: 8 Jul 2024
    6.5
    Medium

    CVE-2024-39895

    Last Modified: 3 Jan 2025

    Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL to overwhelm a server by requesting the same field multiple times in a single query. This can cause the server to perform redundant computations and consume excessive resources, leading to a denial of service for legitimate users. Request to the endpoint /graphql are sent when visualizing graphs generated at a dashboard. By modifying the data sent and duplicating many times the fields a DoS attack is possible. This vulnerability is fixed in 10.12.0.

    Published: 8 Jul 2024
    6.3
    Medium

    CVE-2024-39701

    Last Modified: 4 Sept 2025

    Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true allowing the request to pass. This results in Broken Access Control because the rule fails to do what it was intended to do: Pass rule if **field** matches any of the **values**. This vulnerability is fixed in 10.6.0.

    Published: 8 Jul 2024
    5.3
    Medium

    CVE-2024-39312

    Last Modified: 11 Apr 2025

    Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A bug in the parsing of name constraint extensions in X.509 certificates meant that if the extension included both permitted subtrees and excluded subtrees, only the permitted subtree would be checked. If a certificate included a name which was permitted by the permitted subtree but also excluded by excluded subtree, it would be accepted. Fixed in versions 3.5.0 and 2.19.5.

    Published: 8 Jul 2024
    5.3
    Medium

    CVE-2024-34702

    Last Modified: 15 Apr 2026

    Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names and name constraints. An attacker who presented a certificate chain which contained a very large number of names in the SubjectAlternativeName, signed by a CA certificate which contained a large number of name constraints, could cause a denial of service. The problem has been addressed in Botan 3.5.0 and a partial backport has also been applied and is included in Botan 2.19.5.

    Published: 8 Jul 2024
    5.3
    Medium

    CVE-2024-23562

    Last Modified: 21 Nov 2024

    A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to launch further attacks against the affected system.

    Published: 8 Jul 2024
    5
    Medium

    CVE-2024-39699

    Last Modified: 21 Nov 2024

    Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It was fixed by resolving all DNS names and checking if the requested IP is an internal IP address. However it is possible to bypass this security measure and execute a SSRF using redirects. Directus allows redirects when importing file from the URL and does not check the result URL. Thus, it is possible to execute a request to an internal IP, for example to 127.0.0.1. However, it is blind SSRF, because Directus also uses response interception technique to get the information about the connect from the socket directly and it does not show a response if the IP address is internal. This vulnerability is fixed in 10.9.3.

    Published: 8 Jul 2024
    8.8
    High

    CVE-2023-47677

    Last Modified: 4 Nov 2025

    A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-34435

    Last Modified: 4 Nov 2025

    A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2024-21778

    Last Modified: 4 Nov 2025

    A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this vulnerability.

    Published: 8 Jul 2024
    9.8
    Critical

    CVE-2023-46685

    Last Modified: 4 Nov 2025

    A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-49593

    Last Modified: 4 Nov 2025

    Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-49073

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-48270

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-45742

    Last Modified: 4 Nov 2025

    An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-49595

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-45215

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-47856

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50240

    Last Modified: 4 Nov 2025

    Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `AdvDefaultPreference` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50239

    Last Modified: 4 Nov 2025

    Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `interfacename` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-41251

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50244

    Last Modified: 4 Nov 2025

    Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50243

    Last Modified: 4 Nov 2025

    Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `comment` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50383

    Last Modified: 4 Nov 2025

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50382

    Last Modified: 4 Nov 2025

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `peerPin` request's parameter.

    Published: 8 Jul 2024
    7.2
    High

    CVE-2023-50381

    Last Modified: 4 Nov 2025

    Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.

    Published: 8 Jul 2024