CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-34206

    Last Modified: 9 Apr 2025

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32609

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-32607

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-32606

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

    Published: 9 May 2024
    8.8
    High

    CVE-2024-32605

    Last Modified: 18 Apr 2025

    HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

    Published: 9 May 2024
    8.8
    High

    CVE-2024-34207

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-29166

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.7
    High

    CVE-2024-34217

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29165

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29164

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29163

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34215

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29162

    Last Modified: 18 Apr 2025

    HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-29161

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29160

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29159

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.4
    High

    CVE-2024-29158

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-29157

    Last Modified: 18 Apr 2025

    HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-34351

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-34350

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-33454

    Last Modified: 31 Dec 2025

    Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32739

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32738

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32737

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32736

    Last Modified: 23 Oct 2025

    A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

    Published: 9 May 2024
    8.1
    High

    CVE-2024-34345

    Last Modified: 15 Apr 2026

    The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

    Published: 9 May 2024
    9.8
    Critical

    CVE-2024-32735

    Last Modified: 23 Oct 2025

    An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34354

    Last Modified: 15 Apr 2026

    CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-34352

    Last Modified: 7 Feb 2025

    1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `>` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-4678

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263599.

    Published: 9 May 2024
    8.1
    High

    CVE-2024-32655

    Last Modified: 15 Apr 2026

    Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3.

    Published: 9 May 2024
    6.1
    Medium

    CVE-2024-34074

    Last Modified: 4 Aug 2025

    Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34210

    Last Modified: 9 Apr 2025

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.

    Published: 9 May 2024
    8.8
    High

    CVE-2024-34211

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

    Published: 9 May 2024
    6.8
    Medium

    CVE-2024-32874

    Last Modified: 15 Apr 2026

    Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. This is due to no limitation set on the length of the filename and the costy use of the Unicode normalization with the form NFKD under the hood of `secure_filename()`.

    Published: 9 May 2024
    7.3
    High

    CVE-2024-34212

    Last Modified: 9 Apr 2025

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.

    Published: 9 May 2024
    8.6
    High

    CVE-2024-34219

    Last Modified: 4 Apr 2025

    TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

    Published: 9 May 2024
    6.2
    Medium

    CVE-2024-31803

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.

    Published: 9 May 2024
    3.8
    Low

    CVE-2024-34218

    Last Modified: 4 Apr 2025

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-4677

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/my_student_exam_marks1.php. The manipulation of the argument year leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263598 is the identifier assigned to this vulnerability.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-4676

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/range_grade_text.php. The manipulation of the argument count leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263597 was assigned to this vulnerability.

    Published: 9 May 2024
    8.6
    High

    CVE-2024-23473

    Last Modified: 10 Feb 2025

    The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

    Published: 9 May 2024
    9
    Critical

    CVE-2024-28075

    Last Modified: 10 Feb 2025

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32712

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-32717

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-32719

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP Club Manager WP Club Manager wp-club-manager.This issue affects WP Club Manager: from n/a through <= 2.2.11.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-32724

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-34549

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-34550

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-34556

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4.

    Published: 9 May 2024