CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2024-38471

    Last Modified: 15 Apr 2026

    Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.

    Published: 4 Jul 2024
    8.1
    High

    CVE-2024-38345

    Last Modified: 15 Apr 2026

    A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.

    Published: 4 Jul 2024
    5.4
    Medium

    CVE-2024-38344

    Last Modified: 15 Apr 2026

    A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.

    Published: 4 Jul 2024
    3.1
    Low

    CVE-2024-6501

    Last Modified: 15 Apr 2026

    A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager would crash, leading to a denial of service.

    Published: 4 Jul 2024
    7.8
    High

    CVE-2024-39934

    Last Modified: 15 Apr 2026

    Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.

    Published: 4 Jul 2024
    5.3
    Medium

    CVE-2024-39211

    Last Modified: 15 Apr 2026

    Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the user account exists.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39930

    Last Modified: 11 Apr 2025

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.

    Published: 4 Jul 2024
    4.3
    Medium

    CVE-2023-39327

    Last Modified: 21 Sept 2026

    A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.

    Published: 4 Jul 2024
    9.8
    Critical

    CVE-2024-39165

    Last Modified: 15 Apr 2026

    QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.

    Published: 4 Jul 2024
    6.2
    Medium

    CVE-2024-39884

    Last Modified: 1 Jul 2025

    A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.61, which fixes this issue.

    Published: 4 Jul 2024
    5.4
    Medium

    CVE-2024-39929

    Last Modified: 10 Jul 2025

    Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

    Published: 4 Jul 2024
    8.6
    High

    CVE-2024-39937

    Last Modified: 10 Nov 2025

    supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39931

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows deletion of internal files.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39932

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

    Published: 4 Jul 2024
    7.7
    High

    CVE-2024-39933

    Last Modified: 10 Apr 2025

    Gogs through 0.13.0 allows argument injection during the tagging of a new release.

    Published: 4 Jul 2024
    8.8
    High

    CVE-2024-39935

    Last Modified: 2 Oct 2025

    jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.

    Published: 4 Jul 2024
    9.9
    Critical

    CVE-2024-39943

    Last Modified: 21 Nov 2024

    rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).

    Published: 4 Jul 2024
    6.8
    Medium

    CVE-2024-6505

    Last Modified: 8 Nov 2025

    A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

    Published: 4 Jul 2024
    6.5
    Medium

    CVE-2023-39329

    Last Modified: 21 Sept 2026

    A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

    Published: 4 Jul 2024
    7.5
    High

    CVE-2024-39321

    Last Modified: 25 Nov 2025

    Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.

    Published: 4 Jul 2024
    8.6
    High

    CVE-2024-39936

    Last Modified: 29 Nov 2025

    An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

    Published: 4 Jul 2024
    6.3
    Medium

    CVE-2024-6284

    Last Modified: 26 Sept 2025

    In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go.dev/github.com/google/[email protected] The bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/[email protected]

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6383

    Last Modified: 15 Apr 2026

    The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1

    Published: 3 Jul 2024
    5.7
    Medium

    CVE-2024-39683

    Last Modified: 8 Jan 2025

    ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of the current user agent (browser). Starting in version 2.53.0 and prior to versions 2.53.8, 2.54.5, and 2.55.1, due to a missing check, user sessions without that information (e.g. when created though the session service) were incorrectly listed exposing potentially other user's sessions. Versions 2.55.1, 2.54.5, and 2.53.8 contain a fix for the issue. There is no workaround since a patch is already available.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-37157

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious actor could get the FastImage library to redirect requests to an internal Discourse IP. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. No known workarounds are available.

    Published: 3 Jul 2024
    2.4
    Low

    CVE-2024-36122

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to view email addresses setting is disabled. This issue is patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches. As possible workarounds, either prevent moderators from accessing the review queue or disable the approve suspect users site setting and the must approve users site setting to prevent users from being added to the review queue.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6488

    Last Modified: 13 Feb 2025

    This is REJECTED.

    Published: 3 Jul 2024
    4.2
    Medium

    CVE-2024-35234

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing maliciously crafted meta tags. This issue only affects sites with Content Security Polic (CSP) disabled. The problem has been patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch. As a workaround, ensure CSP is enabled on the forum.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-5887

    Last Modified: 17 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    6.2
    Medium

    CVE-2024-5821

    Last Modified: 15 Apr 2026

    The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.

    Published: 3 Jul 2024
    7.5
    High

    CVE-2024-35227

    Last Modified: 26 Aug 2025

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instance. The problem has been patched in version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch. There are no known workarounds available for this vulnerability.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-31223

    Last Modified: 4 Sept 2025

    Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to communicate with the Fides webserver backend. The value of this variable is a URL which typically includes a private IP address, private domain name, and/or port. A vulnerability present starting in version 2.19.0 and prior to version 2.39.2rc0 allows an unauthenticated attacker to make a HTTP GET request from the Privacy Center that discloses the value of this server-side URL. This could result in disclosure of server-side configuration giving an attacker information on server-side ports, private IP addresses, and/or private domain names. The vulnerability has been patched in Fides version 2.39.2rc0. No known workarounds are available.

    Published: 3 Jul 2024
    6.5
    Medium

    CVE-2024-3332

    Last Modified: 3 Feb 2025

    A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device

    Published: 3 Jul 2024
    6.5
    Medium

    CVE-2024-6052

    Last Modified: 21 Nov 2024

    Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scripts by injecting HTML elements

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-32937

    Last Modified: 4 Nov 2025

    An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6471

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an unknown part of the file sms_setting.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270279.

    Published: 3 Jul 2024
    5.1
    Medium

    CVE-2024-6470

    Last Modified: 5 Apr 2025

    A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php?app=main&inc=feature_inboxgroup&op=list of the component Template Handler. The manipulation of the argument Receiver Number with the input {{`id`}} leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-270278 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jul 2024
    7.2
    High

    CVE-2024-5672

    Last Modified: 15 Apr 2026

    A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

    Published: 3 Jul 2024
    7.5
    High

    CVE-2024-6427

    Last Modified: 21 Nov 2024

    Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, causing the application to loop requests on itself, which could lead to resource consumption and disable the application.

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-6426

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing the API value of the application.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6475

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    —
    Unknown

    CVE-2024-6474

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Jul 2024
    5.1
    Medium

    CVE-2024-6469

    Last Modified: 21 Nov 2024

    A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list of the component Template Handler. The manipulation of the argument IP address with the input {{`id`} leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270277 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jul 2024
    5.3
    Medium

    CVE-2024-6428

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when creating a new user which allows an attacker to specify both a remoteId and the user ID, resulting in creating a user with a user-defined user ID. This can cause some broken functionality in User Management such administrative actions against the user not working.

    Published: 3 Jul 2024
    2.7
    Low

    CVE-2024-39353

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

    Published: 3 Jul 2024
    3.1
    Low

    CVE-2024-39361

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts

    Published: 3 Jul 2024
    8.1
    High

    CVE-2024-39830

    Last Modified: 21 Nov 2024

    Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.

    Published: 3 Jul 2024
    3.1
    Low

    CVE-2024-39807

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.

    Published: 3 Jul 2024
    2.7
    Low

    CVE-2024-36257

    Last Modified: 21 Nov 2024

    Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

    Published: 3 Jul 2024
    6.4
    Medium

    CVE-2024-6263

    Last Modified: 8 Apr 2026

    The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Jul 2024