CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2024-39884

    Last Modified: 1 Jul 2025

    A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.61, which fixes this issue.

    Published: 4 Jul 2024
    5.4
    Medium

    CVE-2024-39929

    Last Modified: 10 Jul 2025

    Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

    Published: 4 Jul 2024
    8.6
    High

    CVE-2024-39937

    Last Modified: 10 Nov 2025

    supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39931

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows deletion of internal files.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39932

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

    Published: 4 Jul 2024
    7.7
    High

    CVE-2024-39933

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows argument injection during the tagging of a new release.

    Published: 4 Jul 2024
    8.8
    High

    CVE-2024-39935

    Last Modified: 2 Oct 2025

    jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39943

    Last Modified: 21 Nov 2024

    rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).

    Published: 4 Jul 2024
    6.8
    Medium

    CVE-2024-6505

    Last Modified: 8 Nov 2025

    A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

    Published: 4 Jul 2024
    6.5
    Medium

    CVE-2023-39329

    Last Modified: 21 Sept 2026

    A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

    Published: 4 Jul 2024
    7.5
    High

    CVE-2024-39321

    Last Modified: 25 Nov 2025

    Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.

    Published: 4 Jul 2024
    8.6
    High

    CVE-2024-39936

    Last Modified: 29 Nov 2025

    An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

    Published: 4 Jul 2024
    6.3
    Medium

    CVE-2024-6284

    Last Modified: 26 Sept 2025

    In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go.dev/github.com/google/[email protected] The bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/[email protected]

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6383

    Last Modified: 15 Apr 2026

    The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

    Published: 3 Jul 2024
    5.7
    Medium

    CVE-2024-39683

    Last Modified: 8 Jan 2025

    ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-37157

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious actor could get the FastImage library to redirect requests to an internal Discourse IP. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. No known workarounds are available.

    Published: 3 Jul 2024
    2.4
    Low

    CVE-2024-36122

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to view email addresses setting is disabled. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. As possible workarounds, either prevent moderators from accessing the review queue or disable the approve suspect users site setting and the must approve users site setting to prevent users from being added to the review queue.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6488

    Last Modified: 13 Feb 2025

    This is REJECTED.

    Published: 3 Jul 2024
    4.2
    Medium

    CVE-2024-35234

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing maliciously crafted meta tags. This issue only affects sites with Content Security Polic (CSP) disabled. The problem has been patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch. As a workaround, ensure CSP is enabled on the forum.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-5887

    Last Modified: 17 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    6.2
    Medium

    CVE-2024-5821

    Last Modified: 15 Apr 2026

    The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.

    Published: 3 Jul 2024
    7.5
    High

    CVE-2024-35227

    Last Modified: 26 Aug 2025

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instance. The problem has been patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch. There are no known workarounds available for this vulnerability.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-31223

    Last Modified: 4 Sept 2025

    Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend. The value of this variable is a URL which typically includes a private IP address, private domain name, and/or port. A vulnerability present starting in version 2.19.0 and prior to version 2.39.2rc0 allows an unauthenticated attacker to make a HTTP GET request from the Privacy Center that discloses the value of this server-side URL. This could result in disclosure of server-side configuration giving an attacker information on server-side ports, private IP addresses, and/or private domain names. The vulnerability has been patched in Fides version 2.39.2rc0. No known workarounds are available.

    Published: 3 Jul 2024
    6.5
    Medium

    CVE-2024-3332

    Last Modified: 3 Feb 2025

    A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device

    Published: 3 Jul 2024
    6.5
    Medium

    CVE-2024-6052

    Last Modified: 21 Nov 2024

    Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-32937

    Last Modified: 4 Nov 2025

    An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6471

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270279.

    Published: 3 Jul 2024
    5.1
    Medium

    CVE-2024-6470

    Last Modified: 5 Apr 2025

    A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php?app=main&inc=feature_inboxgroup&op=list of the component Template Handler. The manipulation of the argument Receiver Number with the input {{`id`}} leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-270278 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jul 2024
    7.2
    High

    CVE-2024-5672

    Last Modified: 15 Apr 2026

    A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

    Published: 3 Jul 2024
    7.5
    High

    CVE-2024-6427

    Last Modified: 21 Nov 2024

    Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-6426

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing the API value of the application.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6475

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6474

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    5.1
    Medium

    CVE-2024-6469

    Last Modified: 21 Nov 2024

    A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list of the component Template Handler. The manipulation of the argument IP address with the input {{`id`} leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270277 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6428

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.

    Published: 3 Jul 2024
    2.7
    Low

    CVE-2024-39353

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

    Published: 3 Jul 2024
    3.1
    Low

    CVE-2024-39361

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-39830

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.

    Published: 3 Jul 2024
    3.1
    Low

    CVE-2024-39807

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.

    Published: 3 Jul 2024
    2.7
    Low

    CVE-2024-36257

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-6263

    Last Modified: 8 Apr 2026

    The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-6340

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 4.10.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 4.10.36 and fully patched in version 4.10.37.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-4482

    Last Modified: 8 Apr 2026

    The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied 'text_days' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jul 2024
    9.1
    Critical

    CVE-2024-37082

    Last Modified: 15 Apr 2026

    When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.  You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_service”.

    Published: 3 Jul 2024
    8.8
    High

    CVE-2024-2376

    Last Modified: 21 Nov 2024

    The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 3 Jul 2024
    5.4
    Medium

    CVE-2024-2375

    Last Modified: 21 Nov 2024

    The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

    Published: 3 Jul 2024
    4.3
    Medium

    CVE-2024-2235

    Last Modified: 21 Nov 2024

    The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack

    Published: 3 Jul 2024
    5.4
    Medium

    CVE-2024-2234

    Last Modified: 21 Nov 2024

    The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks

    Published: 3 Jul 2024
    4.3
    Medium

    CVE-2024-2233

    Last Modified: 21 Nov 2024

    The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

    Published: 3 Jul 2024
    6.5
    Medium

    CVE-2024-2231

    Last Modified: 2 Jan 2026

    The allows any authenticated user to join a private group due to a missing authorization check on a function

    Published: 3 Jul 2024