CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2025-0328

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipulation of the argument code leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13213

    Last Modified: 15 Oct 2025

    A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13212

    Last Modified: 15 Oct 2025

    A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13211

    Last Modified: 15 Oct 2025

    A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Jan 2025
    8.5
    High

    CVE-2024-13206

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2025
    4.2
    Medium

    CVE-2024-13041

    Last Modified: 5 Aug 2025

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-12736

    Last Modified: 12 Jun 2025

    The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-12731

    Last Modified: 21 Apr 2025

    The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 9 Jan 2025
    4.8
    Medium

    CVE-2024-12717

    Last Modified: 21 Apr 2025

    The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-12715

    Last Modified: 17 May 2025

    The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-12714

    Last Modified: 17 May 2025

    The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 9 Jan 2025
    4.2
    Medium

    CVE-2024-10815

    Last Modified: 14 May 2025

    The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2023-27531

    Last Modified: 15 Apr 2026

    There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

    Published: 9 Jan 2025
    3.6
    Low

    CVE-2024-37372

    Last Modified: 15 Apr 2026

    The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not always true. This subtle bug leads to vulnerable edge cases.

    Published: 9 Jan 2025
    5.3
    Medium

    CVE-2024-13199

    Last Modified: 24 Sept 2025

    A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2025
    6.3
    Medium

    CVE-2024-13198

    Last Modified: 24 Sept 2025

    A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-54724

    Last Modified: 15 Apr 2026

    PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.

    Published: 9 Jan 2025
    9.1
    Critical

    CVE-2024-46505

    Last Modified: 15 Apr 2026

    Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

    Published: 9 Jan 2025
    7.8
    High

    CVE-2024-46464

    Last Modified: 15 Apr 2026

    In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute programs with an elevation of privilege.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2023-28354

    Last Modified: 15 Apr 2026

    An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRPE plugin execution. This allows the attacker to escape NRPE plugin execution and execute commands remotely on the target as NT_AUTHORITY\SYSTEM.

    Published: 9 Jan 2025
    —
    Unknown

    CVE-2024-57362

    Last Modified: 3 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation duplicate of CVE-2024-54840. Notes: All CVE users should reference CVE-2024-54840 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-56376

    Last Modified: 16 Jan 2025

    A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.

    Published: 9 Jan 2025
    8
    High

    CVE-2024-54887

    Last Modified: 20 Jun 2025

    TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

    Published: 9 Jan 2025
    6.8
    Medium

    CVE-2024-48806

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field

    Published: 9 Jan 2025
    9.6
    Critical

    CVE-2024-55224

    Last Modified: 20 Jun 2025

    An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.

    Published: 9 Jan 2025
    6.5
    Medium

    CVE-2024-56114

    Last Modified: 16 Jul 2025

    Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-56377

    Last Modified: 16 Jan 2025

    A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (which has been injected into all survey fields) is executed, potentially enabling the execution of arbitrary web scripts.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-42898

    Last Modified: 24 Jun 2025

    A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

    Published: 9 Jan 2025
    8.8
    High

    CVE-2024-51229

    Last Modified: 29 Sept 2025

    Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

    Published: 9 Jan 2025
    6.3
    Medium

    CVE-2024-54762

    Last Modified: 14 May 2025

    Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.

    Published: 9 Jan 2025
    6.3
    Medium

    CVE-2024-54761

    Last Modified: 29 Sept 2025

    BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

    Published: 9 Jan 2025
    9.8
    Critical

    CVE-2024-55225

    Last Modified: 20 Jun 2025

    An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

    Published: 9 Jan 2025
    5.4
    Medium

    CVE-2024-55226

    Last Modified: 24 Jun 2025

    Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

    Published: 9 Jan 2025
    6.1
    Medium

    CVE-2024-55494

    Last Modified: 15 Apr 2026

    A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.

    Published: 9 Jan 2025
    7.5
    High

    CVE-2024-56113

    Last Modified: 15 Apr 2026

    Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.

    Published: 9 Jan 2025
    5.1
    Medium

    CVE-2024-13210

    Last Modified: 22 Aug 2025

    A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jan 2025
    5.1
    Medium

    CVE-2024-13209

    Last Modified: 24 Jun 2025

    A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    5.1
    Medium

    CVE-2024-13205

    Last Modified: 2 Jul 2025

    A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/create_product.php of the component Create Product Page. The manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    —
    Unknown

    CVE-2025-0351

    Last Modified: 19 Nov 2025

    Voluntarily withdrawn

    Published: 8 Jan 2025
    7
    High

    CVE-2025-0283

    Last Modified: 26 Feb 2026

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

    Published: 8 Jan 2025
    9
    Critical

    CVE-2025-0282

    Last Modified: 24 Oct 2025

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

    Published: 8 Jan 2025
    5.3
    Medium

    CVE-2024-13204

    Last Modified: 2 Jul 2025

    A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /blog-details.php. The manipulation of the argument blog_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    6.9
    Medium

    CVE-2024-13203

    Last Modified: 2 Jul 2025

    A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    5.1
    Medium

    CVE-2024-13202

    Last Modified: 22 Aug 2025

    A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Handler. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jan 2025
    5.1
    Medium

    CVE-2024-13201

    Last Modified: 22 Aug 2025

    A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    6.9
    Medium

    CVE-2024-13200

    Last Modified: 22 Aug 2025

    A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Jan 2025
    5.3
    Medium

    CVE-2024-13190

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jan 2025
    1.9
    Low

    CVE-2024-53995

    Last Modified: 15 Apr 2026

    SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter.

    Published: 8 Jan 2025
    3.4
    Low

    CVE-2024-54010

    Last Modified: 22 Sept 2026

    A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.

    Published: 8 Jan 2025
    6.3
    Medium

    CVE-2025-22145

    Last Modified: 15 Apr 2026

    Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6.

    Published: 8 Jan 2025