CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-32621

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32620

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32619

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32618

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-32617

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32616

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-32615

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-32614

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-34209

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32613

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-34213

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-34200

    Last Modified: 3 Apr 2025

    TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34201

    Last Modified: 3 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-32612

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-32611

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34202

    Last Modified: 3 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.

    Published: 9 May 2024
    3.8
    Low

    CVE-2024-34203

    Last Modified: 3 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-34204

    Last Modified: 9 Apr 2025

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34205

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-32610

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34206

    Last Modified: 9 Apr 2025

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32609

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-32607

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-32606

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

    Published: 9 May 2024
    8.8
    High

    CVE-2024-32605

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

    Published: 9 May 2024
    8.8
    High

    CVE-2024-34207

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-29166

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.7
    High

    CVE-2024-34217

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29165

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29164

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29163

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34215

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29162

    Last Modified: 18 Apr 2025

    HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-29161

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29160

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29159

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29158

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29157

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-34351

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-34350

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-33454

    Last Modified: 31 Dec 2025

    Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32739

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32738

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32737

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32736

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

    Published: 9 May 2024
    8.1
    High

    CVE-2024-34345

    Last Modified: 15 Apr 2026

    The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-32735

    Last Modified: 23 Oct 2025

    An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34354

    Last Modified: 15 Apr 2026

    CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34352

    Last Modified: 7 Feb 2025

    1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-4678

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263599.

    Published: 9 May 2024