CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2024-7251 Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Inte... | 7.8 | HIGH | — | 0 |
| CVE-2024-7252 Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Inte... | 7.8 | HIGH | — | 0 |
| CVE-2024-7212 A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504. This issue affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation... | 8.8 | HIGH | — | 0 |
| CVE-2024-7213 A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504. Affected is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the a... | 8.8 | HIGH | — | 0 |
| CVE-2024-7214 A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipu... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-7215 A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832 and classified as critical. Affected by this issue is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the a... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-7216 A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknown part of the file /etc/shadow.sample. The manipulation leads to use of hard-cod... | 2.6 | LOW | — | 0 |
| CVE-2024-7217 A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the ... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-40094 GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixe... | 5.3 | MEDIUM | — | 0 |
| CVE-2024-7222 A vulnerability, which was classified as critical, was found in SourceCodester Lot Reservation Management System 1.0. Affected is an unknown function of the file /home.php. The manipulation of the arg... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-42123 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will... | 4.4 | MEDIUM | — | 0 |
| CVE-2024-38432 Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File | 5.5 | MEDIUM | — | 0 |
| CVE-2024-42144 In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/mediatek/lvts_thermal: Check NULL ptr on lvts_data Verify that lvts_data is not NULL before using it. | 5.5 | MEDIUM | — | 0 |
| CVE-2024-42155 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys is accessible, t... | 1.9 | LOW | — | 0 |
| CVE-2024-42158 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix w... | 4.1 | MEDIUM | — | 0 |
| CVE-2024-42162 In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact that the NIC might send us stats for a subset o... | 7.0 | HIGH | — | 0 |
| CVE-2024-42227 In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix overlapping copy within dml_core_mode_programming [WHY] &mode_lib->mp.Watermark and &locals->Watermark are th... | 4.7 | MEDIUM | — | 0 |
| CVE-2024-41702 SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 9.8 | CRITICAL | — | 0 |
| CVE-2024-42231 In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix calc_available_free_space() for zoned mode calc_available_free_space() returns the total size of metadata (or sy... | 5.5 | MEDIUM | — | 0 |
| CVE-2024-7223 A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_model.ph... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-7224 A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /lot_details.php. The man... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-38429 Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties | 7.5 | HIGH | — | 0 |
| CVE-2024-38430 Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 5.4 | MEDIUM | — | 0 |
| CVE-2024-38431 Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy | 5.3 | MEDIUM | — | 0 |
| CVE-2024-40895 FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain cond... | 6.4 | MEDIUM | — | 0 |
| CVE-2024-41141 Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Manageme... | 6.1 | MEDIUM | — | 0 |
| CVE-2024-41694 Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 5.3 | MEDIUM | — | 0 |
| CVE-2024-41695 Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory | 7.5 | HIGH | — | 0 |
| CVE-2024-41696 Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 7.5 | HIGH | — | 0 |
| CVE-2024-7225 A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy of the com... | 3.5 | LOW | — | 0 |
| CVE-2024-7226 A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user of the ... | 4.3 | MEDIUM | — | 0 |
| CVE-2024-41701 AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 5.3 | MEDIUM | — | 0 |
| CVE-2024-7127 Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the username during... | 6.1 | MEDIUM | — | 0 |
| CVE-2024-6699 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon MA7: from v3.0... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-37165 Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-37299 Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnera... | 4.9 | MEDIUM | — | 0 |
| CVE-2024-41916 A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an atta... | 6.8 | MEDIUM | — | 0 |
| CVE-2024-39320 Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by... | 6.1 | MEDIUM | — | 0 |
| CVE-2024-4188 Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4. | N/A | NONE | — | 0 |
| CVE-2024-41802 Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to ob... | 8.1 | HIGH | — | 0 |
| CVE-2024-41803 Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to ob... | 4.9 | MEDIUM | — | 0 |
| CVE-2024-41944 Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain... | 6.5 | MEDIUM | — | 0 |
| CVE-2024-45769 A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash. | 5.5 | MEDIUM | — | 0 |
| CVE-2024-45770 A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which i... | 4.4 | MEDIUM | — | 0 |
| CVE-2024-8354 A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivil... | 5.5 | MEDIUM | — | 0 |
| CVE-2024-41721 An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution. | 8.1 | HIGH | — | 0 |
| CVE-2023-47480 An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function. | 8.4 | HIGH | — | 0 |
| CVE-2024-37879 Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo... | 4.8 | MEDIUM | — | 0 |
| CVE-2024-41930 Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user ... | 6.1 | MEDIUM | — | 0 |
| CVE-2024-37185 in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | 8.2 | HIGH | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.