6.4
    Medium

    CVE-2024-43018

    Last Modified: 6 Aug 2025

    Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in advanced way in /admin.php?page=user_list.

    Published:29 Jul 2025
    Low

    CVE-2024-42992

    Last Modified: 26 Aug 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:23 Aug 2024
    9.8
    Critical

    CVE-2024-42919

    Last Modified: 12 Nov 2025

    eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

    Published:20 Aug 2024
    7.5
    High

    CVE-2024-42861

    Last Modified: 18 Mar 2025

    An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

    Published:23 Sept 2024
    9.8
    Critical

    CVE-2024-42850

    Last Modified: 5 Jun 2025

    An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

    Published:16 Aug 2024
    6.5
    Medium

    CVE-2024-42849

    Last Modified: 5 Jun 2025

    An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

    Published:16 Aug 2024
    8
    High

    CVE-2024-42845

    Last Modified: 15 Apr 2026

    An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

    Published:23 Aug 2024
    6.1
    Medium

    CVE-2024-42834

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.

    Published:13 Nov 2024
    6.1
    Medium

    CVE-2024-42831

    Last Modified: 13 Apr 2025

    A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.

    Source:arfaoui haythem
    Published:7 Oct 2024
    5.4
    Medium

    CVE-2024-42758

    Last Modified: 15 Apr 2026

    A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki (Open Source Wiki Engine). A malicious attacker can input XSS payloads for example when creating or editing existing page, to trigger the XSS on Dokuwiki, which is then stored in .txt file (due to nature of how Dokuwiki is designed), which presents stored XSS.

    Published:16 Aug 2024
    8.8
    High

    CVE-2024-42658

    Last Modified: 20 Aug 2024

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

    Published:19 Aug 2024
    7.5
    High

    CVE-2024-42657

    Last Modified: 20 Aug 2024

    An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process

    Published:19 Aug 2024
    6.7
    Medium

    CVE-2024-42642

    Last Modified: 5 Feb 2026

    Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

    Published:4 Sept 2024
    9.8
    Critical

    CVE-2024-42640

    Last Modified: 13 Apr 2025

    angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Source:Ravindu Wickramasinghe
    Published:11 Oct 2024
    7.3
    High

    CVE-2024-42471

    Last Modified: 30 Apr 2025

    actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

    Source:cybersploit
    Published:2 Sept 2024
    5.3
    Medium

    CVE-2024-42461

    Last Modified: 3 Nov 2025

    In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

    Published:2 Aug 2024
    9.9
    Critical

    CVE-2024-42448

    Last Modified: 15 Apr 2026

    From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

    Published:11 Dec 2024
    8.3
    High

    CVE-2024-42370

    Last Modified: 15 Apr 2026

    Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the `DOCS_PREVIEW_DEPLOY_TOKEN` is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue.

    Published:9 Aug 2024
    7.4
    High

    CVE-2024-42365

    Last Modified: 3 Nov 2025

    Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the `/etc/asterisk/` directory. This occurs because they are able to curl remote files and write them to disk, but are also able to append to existing files using the `FILE` function inside the `SET` application. This issue may result in privilege escalation, remote code execution and/or blind server-side request forgery with arbitrary protocol. Asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2 contain a fix for this issue.

    Published:8 Aug 2024
    6.5
    Medium

    CVE-2024-42364

    Last Modified: 12 Sept 2024

    Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will ask a user to visit his/her website. The attacker website will then change the DNS records of their domain from their IP address to the internal IP address of the homepage instance. To tell which IP addresses are valid, we can rebind a subdomain to each IP address we want to check, and see if there is a response. Once potential candidates have been found, the attacker can launch the attack by reading the response of the webserver after the IP address has changed. When the attacker domain is fetched, the response will be from the homepage instance, not the attacker website, because the IP address has been changed. Due to a lack of authentication, a user’s private information such as API keys (fixed after first report) and other private information can then be extracted by the attacker website.

    Published:23 Aug 2024
    7.6
    High

    CVE-2024-42346

    Last Modified: 15 Aug 2025

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:20 Sept 2024
    9.9
    Critical

    CVE-2024-42327

    Last Modified: 16 Apr 2025

    A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

    Source:m4nb4
    Published:27 Nov 2024
    8.8
    High

    CVE-2024-42323

    Last Modified: 1 Jul 2025

    SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.0. Users are recommended to upgrade to version 1.6.0, which fixes the issue.

    Published:21 Sept 2024
    9.1
    Critical

    CVE-2024-42049

    Last Modified: 9 Jun 2025

    TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

    Source:Ionut Zevedei
    Published:28 Jul 2024
    9.3
    Critical

    CVE-2024-42009

    Last Modified: 4 Nov 2025

    A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

    Published:5 Aug 2024
    9.3
    Critical

    CVE-2024-42008

    Last Modified: 13 Mar 2025

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

    Published:5 Aug 2024
    5.8
    Medium

    CVE-2024-42007

    Last Modified: 15 Apr 2026

    SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.

    Published:26 Jul 2024
    6.6
    Medium

    CVE-2024-41997

    Last Modified: 15 Apr 2026

    An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell` intent that when clicked by the victim results in command execution on the victim's machine.

    Published:14 Oct 2024
    8.8
    High

    CVE-2024-41992

    Last Modified: 15 Apr 2026

    Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

    Published:11 Nov 2024
    6.6
    Medium

    CVE-2024-41958

    Last Modified: 20 Sept 2024

    mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other accounts that are otherwise secured with 2FA. To exploit this vulnerability, the attacker must first have access to an account within the system and possess the credentials of the target account that has 2FA enabled. By leveraging these credentials, the attacker can circumvent the 2FA process and gain access to the protected account. This issue has been addressed in the `2024-07` release. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:5 Aug 2024
    9.1
    Critical

    CVE-2024-41947

    Last Modified: 15 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.8 and 16.3.0RC1.

    Source:Siddhartha Naik
    Published:31 Jul 2024
    7
    High

    CVE-2024-41817

    Last Modified: 20 Nov 2025

    ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.

    Published:27 Jul 2024
    9.1
    Critical

    CVE-2024-41713

    Last Modified: 4 Nov 2025

    A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

    Published:21 Oct 2024
    8.6
    High

    CVE-2024-41662

    Last Modified: 21 Nov 2024

    VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary JavaScript code through which remote code execution can be achieved. A patch for this issue is available at commit f1af78573a0ef51d6ef6a0bc4080cddc8f30a545. Other mitigation strategies include implementing rigorous input sanitization for all Markdown content and utilizing a secure Markdown parser that appropriately escapes or strips potentially dangerous content.

    Published:24 Jul 2024
    9.8
    Critical

    CVE-2024-41651

    Last Modified: 9 Oct 2024

    An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).

    Published:12 Aug 2024
    6.1
    Medium

    CVE-2024-41640

    Last Modified: 15 Apr 2026

    Cross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request using the id parameter.

    Published:29 Jul 2024
    7.5
    High

    CVE-2024-41628

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

    Published:26 Jul 2024
    9.8
    Critical

    CVE-2024-41570

    Last Modified: 29 Aug 2024

    An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.

    Published:9 Aug 2024
    6.1
    Medium

    CVE-2024-41505

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor).

    Published:10 Jun 2025
    6.1
    Medium

    CVE-2024-41504

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of the application when creating or editing an "Atividade" (activity), the form field "Descrico" allows injection of JavaScript.

    Published:10 Jun 2025
    6.1
    Medium

    CVE-2024-41503

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function.

    Published:10 Jun 2025
    6.1
    Medium

    CVE-2024-41502

    Last Modified: 1 Oct 2025

    Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the "Pessoas" (persons) section when creating or editing either a legal or a natural person.

    Published:10 Jun 2025
    4.8
    Medium

    CVE-2024-41453

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

    Published:15 Jan 2025
    6.1
    Medium

    CVE-2024-41358

    Last Modified: 4 Feb 2026

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

    Source:CodeSecLab
    Published:29 Aug 2024
    7.1
    High

    CVE-2024-41357

    Last Modified: 2 Dec 2025

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

    Source:CodeSecLab
    Published:26 Jul 2024
    8.8
    High

    CVE-2024-41319

    Last Modified: 21 Nov 2024

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

    Published:23 Jul 2024
    Unknown

    CVE-2024-41312

    https://github.com/Amal264882/CVE-2024-41312.

    Unknown

    CVE-2024-41302

    https://github.com/patrickdeanramos/CVE-2024-41302-Bookea-tu-Mesa-is-vulnerable-to-SQL-Injection

    Unknown

    CVE-2024-41301

    https://github.com/patrickdeanramos/CVE-2024-41301-Bookea-tu-Mesa-is-vulnerable-to-Stored-Cross-Site-Scripting

    8.1
    High

    CVE-2024-41290

    Last Modified: 23 Apr 2025

    FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

    Published:2 Oct 2024
    Items Per Page