CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-36994

    Last Modified: 28 Feb 2025

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View and Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.

    Published: 1 Jul 2024
    7.1
    High

    CVE-2024-36989

    Last Modified: 28 Feb 2025

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.

    Published: 1 Jul 2024
    4.3
    Medium

    CVE-2024-36987

    Last Modified: 28 Feb 2025

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the admin or power Splunk roles could upload a file with an arbitrary extension using the indexing/preview REST endpoint.

    Published: 1 Jul 2024
    6
    Medium

    CVE-2024-20399

    Last Modified: 28 Oct 2025

    A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode

    Published: 1 Jul 2024
    6.1
    Medium

    CVE-2024-36422

    Last Modified: 21 Nov 2024

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `api/v1/chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted URL that injects Javascript into the user sessions, allowing the attacker to steal information, create false popups, or even redirect the user to other websites without interaction. If the chatflow ID is not found, its value is reflected in the 404 page, which has type text/html. This allows an attacker to attach arbitrary scripts to the page, allowing an attacker to steal sensitive information. This XSS may be chained with the path injection to allow an attacker without direct access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-36421

    Last Modified: 21 Nov 2024

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may be able to make requests to Flowise, stealing information from the user. This CORS misconfiguration may be chained with the path injection to allow an attacker attackers without access to Flowise to read arbitrary files from the Flowise server. As of time of publication, no known patches are available.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-36420

    Last Modified: 21 Nov 2024

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are available.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-36401

    Last Modified: 24 Oct 2025

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed.

    Published: 1 Jul 2024
    7
    High

    CVE-2024-6376

    Last Modified: 21 Nov 2024

    MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2

    Published: 1 Jul 2024
    5.4
    Medium

    CVE-2024-6375

    Last Modified: 21 Nov 2024

    A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.

    Published: 1 Jul 2024
    4.5
    Medium

    CVE-2024-34696

    Last Modified: 21 Nov 2024

    GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and 2.25.1, GeoServer's Server Status page and REST API lists all environment variables and Java properties to any GeoServer user with administrative rights as part of those modules' status message. These variables/properties can also contain sensitive information, such as database passwords or API keys/tokens. Additionally, many community-developed GeoServer container images `export` other credentials from their start-up scripts as environment variables to the GeoServer (`java`) process. The precise scope of the issue depends on which container image is used and how it is configured. The `about status` API endpoint which powers the Server Status page is only available to administrators.Depending on the operating environment, administrators might have legitimate access to credentials in other ways, but this issue defeats more sophisticated controls (like break-glass access to secrets or role accounts).By default, GeoServer only allows same-origin authenticated API access. This limits the scope for a third-party attacker to use an administrator’s credentials to gain access to credentials. The researchers who found the vulnerability were unable to determine any other conditions under which the GeoServer REST API may be available more broadly. Users should update container images to use GeoServer 2.24.4 or 2.25.1 to get the bug fix. As a workaround, leave environment variables and Java system properties hidden by default. Those who provide the option to re-enable it should communicate the impact and risks so that users can make an informed choice.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2024-23380

    Last Modified: 21 Nov 2024

    Memory corruption while handling user packets during VBO bind operation.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2024-23373

    Last Modified: 21 Nov 2024

    Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2024-23372

    Last Modified: 21 Nov 2024

    Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

    Published: 1 Jul 2024
    7.8
    High

    CVE-2024-23368

    Last Modified: 21 Nov 2024

    Memory corruption when allocating and accessing an entry in an SMEM partition.

    Published: 1 Jul 2024
    6.8
    Medium

    CVE-2024-21482

    Last Modified: 21 Nov 2024

    Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

    Published: 1 Jul 2024
    7.3
    High

    CVE-2024-21469

    Last Modified: 21 Nov 2024

    Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-21466

    Last Modified: 21 Nov 2024

    Information disclosure while parsing sub-IE length during new IE generation.

    Published: 1 Jul 2024
    7.8
    High

    CVE-2024-21465

    Last Modified: 21 Nov 2024

    Memory corruption while processing key blob passed by the user.

    Published: 1 Jul 2024
    7.1
    High

    CVE-2024-21462

    Last Modified: 21 Nov 2024

    Transient DOS while loading the TA ELF file.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2024-21461

    Last Modified: 21 Nov 2024

    Memory corruption while performing finish HMAC operation when context is freed by keymaster.

    Published: 1 Jul 2024
    7.1
    High

    CVE-2024-21460

    Last Modified: 21 Nov 2024

    Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-21458

    Last Modified: 21 Nov 2024

    Information disclosure while handling SA query action frame.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-21457

    Last Modified: 21 Nov 2024

    INformation disclosure while handling Multi-link IE in beacon frame.

    Published: 1 Jul 2024
    6.5
    Medium

    CVE-2024-21456

    Last Modified: 21 Nov 2024

    Information Disclosure while parsing beacon frame in STA.

    Published: 1 Jul 2024
    8.4
    High

    CVE-2023-43554

    Last Modified: 11 Aug 2025

    Memory corruption while processing IOCTL handler in FastRPC.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-24749

    Last Modified: 4 Nov 2025

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existing input validation in the GeoWebCache ByteStreamController class and read arbitrary classpath resources with specific file name extensions. If GeoServer is also deployed as a web archive using the data directory embedded in the `geoserver.war` file (rather than an external data directory), it will likely be possible to read specific resources to gain administrator privileges. However, it is very unlikely that production environments will be using the embedded data directory since, depending on how GeoServer is deployed, it will be erased and re-installed (which would also reset to the default password) either every time the server restarts or every time a new GeoServer WAR is installed and is therefore difficult to maintain. An external data directory will always be used if GeoServer is running in standalone mode (via an installer or a binary). Versions 2.23.5 and 2.24.3 contain a patch for the issue. Some workarounds are available. One may change from a Windows environment to a Linux environment; or change from Apache Tomcat to Jetty application server. One may also disable anonymous access to the embeded GeoWebCache administration and status pages.

    Published: 1 Jul 2024
    5.3
    Medium

    CVE-2024-6050

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions from 4.0 before 4.9.10, from 5.0 before 6.2.12.

    Published: 1 Jul 2024
    9.1
    Critical

    CVE-2024-6425

    Last Modified: 22 Oct 2025

    Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" and in the parameters "UserName=<RANDOMUSER>&Password=<PASSWORD>&ConfirmPassword=<PASSWORD-REPEAT>".

    Published: 1 Jul 2024
    9.3
    Critical

    CVE-2024-6424

    Last Modified: 22 Oct 2025

    External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL INTERNA|IP/HOST" to read the source code of web files, read internal files or access network resources.

    Published: 1 Jul 2024
    8.7
    High

    CVE-2024-4007

    Last Modified: 19 Dec 2025

    Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

    Published: 1 Jul 2024
    5.1
    Medium

    CVE-2024-39430

    Last Modified: 21 Nov 2024

    In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 1 Jul 2024
    5.1
    Medium

    CVE-2024-39429

    Last Modified: 21 Nov 2024

    In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

    Published: 1 Jul 2024
    6.8
    Medium

    CVE-2024-39428

    Last Modified: 21 Nov 2024

    In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 1 Jul 2024
    5.1
    Medium

    CVE-2024-39427

    Last Modified: 21 Nov 2024

    In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 1 Jul 2024
    8.1
    High

    CVE-2024-6387

    Last Modified: 31 Aug 2026

    A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

    Published: 1 Jul 2024
    4.8
    Medium

    CVE-2024-6130

    Last Modified: 1 May 2025

    The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 1 Jul 2024
    5.5
    Medium

    CVE-2024-4934

    Last Modified: 1 May 2025

    The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 1 Jul 2024
    7.8
    High

    CVE-2024-0153

    Last Modified: 27 Mar 2025

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.

    Published: 1 Jul 2024
    6.7
    Medium

    CVE-2024-20081

    Last Modified: 13 Mar 2025

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-20080

    Last Modified: 28 May 2025

    In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.

    Published: 1 Jul 2024
    6.7
    Medium

    CVE-2024-20079

    Last Modified: 26 Feb 2026

    In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: MSV-1491.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-20078

    Last Modified: 28 May 2025

    In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-20076

    Last Modified: 28 May 2025

    In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297806; Issue ID: MSV-1481.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-20077

    Last Modified: 28 May 2025

    In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01297807; Issue ID: MSV-1482.

    Published: 1 Jul 2024
    7.2
    High

    CVE-2024-3123

    Last Modified: 15 Apr 2026

    CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.

    Published: 1 Jul 2024
    4.9
    Medium

    CVE-2024-3122

    Last Modified: 15 Apr 2026

    CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

    Published: 1 Jul 2024
    4
    Medium

    CVE-2024-38480

    Last Modified: 15 Apr 2026

    "Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.

    Published: 1 Jul 2024
    7.5
    High

    CVE-2024-39249

    Last Modified: 15 Apr 2026

    Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input.

    Published: 1 Jul 2024
    9.8
    Critical

    CVE-2024-39017

    Last Modified: 15 Apr 2026

    agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 1 Jul 2024