CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2024-25366

    Last Modified: 2 Apr 2025

    Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.

    Published: 20 Feb 2024
    3.3
    Low

    CVE-2024-25196

    Last Modified: 2 Apr 2025

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.

    Published: 20 Feb 2024
    6.5
    Medium

    CVE-2024-25197

    Last Modified: 2 Apr 2025

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

    Published: 20 Feb 2024
    9.1
    Critical

    CVE-2024-25198

    Last Modified: 2 Apr 2025

    Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

    Published: 20 Feb 2024
    8.1
    High

    CVE-2024-25199

    Last Modified: 2 Apr 2025

    Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

    Published: 20 Feb 2024
    8.1
    High

    CVE-2024-25262

    Last Modified: 15 Apr 2026

    texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.

    Published: 20 Feb 2024
    4
    Medium

    CVE-2024-25260

    Last Modified: 25 Apr 2025

    elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

    Published: 20 Feb 2024
    7.5
    High

    CVE-2024-1647

    Last Modified: 3 Dec 2025

    Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.

    Published: 19 Feb 2024
    7.2
    High

    CVE-2024-1297

    Last Modified: 20 Apr 2026

    Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

    Published: 19 Feb 2024
    7.5
    High

    CVE-2024-26134

    Last Modified: 13 Feb 2025

    cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.

    Published: 19 Feb 2024
    5.8
    Medium

    CVE-2024-26129

    Last Modified: 17 Jan 2025

    PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. A patch is available in version 8.1.4.

    Published: 19 Feb 2024
    9
    Critical

    CVE-2023-6260

    Last Modified: 5 Feb 2025

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This issue affects ACS100 (Network Adjacent Access), ACS300 (Physical Access): from 5.2.4 before 6.2.4.3.

    Published: 19 Feb 2024
    7.1
    High

    CVE-2023-6259

    Last Modified: 1 Apr 2025

    Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.

    Published: 19 Feb 2024
    7.6
    High

    CVE-2024-0715

    Last Modified: 12 Feb 2025

    Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

    Published: 19 Feb 2024
    7.5
    High

    CVE-2024-1552

    Last Modified: 27 Mar 2025

    Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    7.5
    High

    CVE-2024-1546

    Last Modified: 27 Mar 2025

    When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    6.5
    Medium

    CVE-2024-1547

    Last Modified: 28 Mar 2025

    Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    6.1
    Medium

    CVE-2024-1549

    Last Modified: 27 Mar 2025

    If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    6.1
    Medium

    CVE-2024-1551

    Last Modified: 2 Apr 2025

    Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    4.3
    Medium

    CVE-2024-1548

    Last Modified: 27 Mar 2025

    A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    6.1
    Medium

    CVE-2024-1550

    Last Modified: 27 Mar 2025

    A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    8.1
    High

    CVE-2024-1553

    Last Modified: 27 Mar 2025

    Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

    Published: 19 Feb 2024
    4.6
    Medium

    CVE-2024-25640

    Last Modified: 10 Dec 2024

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations in versions prior to v2.4.0. The vulnerability may allow an attacker to inject malicious scripts into the application, which could then be executed when a user visits the affected locations. This could lead to unauthorized access, data theft, or other related malicious activities. An attacker need to be authenticated on the application to exploit this vulnerability. The issue is fixed in version v2.4.0 of iris-web. No workarounds are available.

    Published: 19 Feb 2024
    9.9
    Critical

    CVE-2024-1644

    Last Modified: 31 Dec 2024

    Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

    Published: 19 Feb 2024
    7.2
    High

    CVE-2024-25634

    Last Modified: 18 Dec 2024

    alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue.

    Published: 19 Feb 2024
    10
    Critical

    CVE-2024-1651

    Last Modified: 12 Feb 2025

    Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

    Published: 19 Feb 2024
    8.8
    High

    CVE-2024-25635

    Last Modified: 18 Dec 2024

    alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using the `http://192.168.26.128:8080/admin/api/users/<user_id>` endpoint, which exposes the details of the provided user ID. This may also expose the API KEY in the username of the user. Version 2.0-M4-2402 fixes this issue.

    Published: 19 Feb 2024
    7.1
    High

    CVE-2024-25636

    Last Modified: 5 Feb 2025

    Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Misskey instance fetch it, if the remote server accepts arbitrary user uploads. The vulnerability allows a threat actor to impersonate and take over an account on a remote server that satisfies all of the following properties: allows the threat actor to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as legitimate Activity Streams actors; and serves user-uploaded document in response to requests with an `Accept` header value of the Activity Streams media type. Version 2024.2.0 contains a patch for the issue.

    Published: 19 Feb 2024
    8.8
    High

    CVE-2024-25626

    Last Modified: 3 Feb 2025

    Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a crafted HTTP request. Authentication is not necessary. Toaster server execution has to be specifically run and is not the default for Bitbake command line builds, it is only used for the Toaster web based user interface to Bitbake. The fix has been backported to the bitbake included with Yocto Project 5.0, 3.1.31, 4.0.16, and 4.3.2.

    Published: 19 Feb 2024
    9.6
    Critical

    CVE-2023-50257

    Last Modified: 2 Jan 2026

    eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, all the Subscribers (Listeners) connected to the Publisher (Talker) will not receive any data and their connection will be disconnected. Moreover, if this disconnection packet is sent continuously, the Subscribers (Listeners) trying to connect will not be able to do so. Since the initial commit of the `SecurityManager.cpp` code (`init`, `on_process_handshake`) on Nov 8, 2016, the Disconnect Vulnerability in RTPS Packets Used by SROS2 has been present prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7.

    Published: 19 Feb 2024
    8.2
    High

    CVE-2024-1638

    Last Modified: 24 Apr 2025

    The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that LE Secure Connections is used for read/write access, however this is only true when it is combined with other permissions, namely BT_GATT_PERM_READ_ENCRYPT/BT_GATT_PERM_READ_AUTHEN (for read) or BT_GATT_PERM_WRITE_ENCRYPT/BT_GATT_PERM_WRITE_AUTHEN (for write), if these additional permissions are not set (even in secure connections only mode) then the stack does not perform any permission checks on these characteristics and they can be freely written/read.

    Published: 19 Feb 2024
    3.5
    Low

    CVE-2024-25983

    Last Modified: 23 Jan 2025

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

    Published: 19 Feb 2024
    4.3
    Medium

    CVE-2024-25982

    Last Modified: 24 Apr 2025

    The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

    Published: 19 Feb 2024
    4.3
    Medium

    CVE-2024-25981

    Last Modified: 23 Jan 2025

    Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

    Published: 19 Feb 2024
    4.3
    Medium

    CVE-2024-25980

    Last Modified: 23 Jan 2025

    Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

    Published: 19 Feb 2024
    5.3
    Medium

    CVE-2024-25979

    Last Modified: 23 Jan 2025

    The URL parameters accepted by forum search were not limited to the allowed parameters.

    Published: 19 Feb 2024
    7.5
    High

    CVE-2024-25978

    Last Modified: 23 Jan 2025

    Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

    Published: 19 Feb 2024
    8.1
    High

    CVE-2024-25625

    Last Modified: 1 Apr 2025

    Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability involves a Host Header Injection in the `invitationLinkAction` function of the UserController, specifically in the way `$loginUrl` trusts user input. The host header from incoming HTTP requests is used unsafely when generating URLs. An attacker can manipulate the HTTP host header in requests to the /admin/user/invitationlink endpoint, resulting in the generation of URLs with the attacker's domain. In fact, if a host header is injected in the POST request, the $loginURL parameter is constructed with this unvalidated host header. It is then used to send an invitation email to the provided user. This vulnerability can be used to perform phishing attacks by making the URLs in the invitation links emails point to an attacker-controlled domain. Version 1.3.4 contains a patch for the vulnerability. The maintainers recommend validating the host header and ensuring it matches the application's domain. It would also be beneficial to use a default trusted host or hostname if the incoming host header is not recognized or is absent.

    Published: 19 Feb 2024
    8.5
    High

    CVE-2024-25623

    Last Modified: 18 Dec 2024

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't check that the response from the remote server has a `Content-Type` header value of the Activity Streams media type, which allows a threat actor to upload a crafted Activity Streams document to a remote server and make a Mastodon server fetch it, if the remote server accepts arbitrary user uploads. The vulnerability allows a threat actor to impersonate an account on a remote server that satisfies all of the following properties: allows the attacker to register an account; accepts arbitrary user-uploaded documents and places them on the same domain as the ActivityPub actors; and serves user-uploaded document in response to requests with an `Accept` header value of the Activity Streams media type. Versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19 contain a fix for this issue.

    Published: 19 Feb 2024
    —
    Unknown

    CVE-2024-27089

    Last Modified: 26 Feb 2024

    This candidate was withdrawn by its CNA. Further investigation showed that it was not in the allowed scope of that CNA's CVE ID assignments.

    Published: 19 Feb 2024
    —
    Unknown

    CVE-2024-27084

    Last Modified: 26 Feb 2024

    This CVE is a duplicate of CVE-2024-1631.

    Published: 19 Feb 2024
    —
    Unknown

    CVE-2024-26701

    Last Modified: 3 Apr 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Feb 2024
    2
    Low

    CVE-2024-1633

    Last Modified: 24 Jan 2025

    During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_descs”. For each image, the bl2 reads the image length and destination from the image’s certificate. Because of the way of reading from the image, which base on 32-bit unsigned integer value, it can result to an integer overflow. An attacker can bypass memory range restriction and write data out of buffer bounds, which could result in bypass of secure boot. Affected git version from c2f286820471ed276c57e603762bd831873e5a17 until (not 

    Published: 19 Feb 2024
    6.8
    Medium

    CVE-2024-1346

    Last Modified: 24 Mar 2025

    Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.

    Published: 19 Feb 2024
    6.8
    Medium

    CVE-2024-1345

    Last Modified: 24 Mar 2025

    Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.

    Published: 19 Feb 2024
    6.8
    Medium

    CVE-2024-1344

    Last Modified: 24 Mar 2025

    Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x86)%\LaborOfficeFree\' directory. This user can log in remotely and has root-like privileges.

    Published: 19 Feb 2024
    4.7
    Medium

    CVE-2024-1343

    Last Modified: 24 Mar 2025

    A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'.

    Published: 19 Feb 2024
    5.9
    Medium

    CVE-2024-1580

    Last Modified: 13 Feb 2025

    An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

    Published: 19 Feb 2024
    7.3
    High

    CVE-2024-22017

    Last Modified: 15 Apr 2026

    setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

    Published: 19 Feb 2024
    6
    Medium

    CVE-2024-26328

    Last Modified: 7 May 2025

    An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

    Published: 19 Feb 2024