CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-55595

    Last Modified: 10 Jun 2025

    Not used

    Published: 9 Dec 2024
    3.1
    Low

    CVE-2024-46901

    Last Modified: 15 Jul 2025

    Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not affected.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-12307

    Last Modified: 15 Apr 2026

    A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability exists due to missing access control checks in the student editing functionality. At the time of publication of the CVE no patch is available.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-12306

    Last Modified: 15 Apr 2026

    Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-12305

    Last Modified: 15 Apr 2026

    An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.

    Published: 9 Dec 2024
    6.1
    Medium

    CVE-2024-9651

    Last Modified: 6 May 2025

    The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53285

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53284

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53283

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53282

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53281

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53279

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.9
    Medium

    CVE-2024-53280

    Last Modified: 4 Aug 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-12360

    Last Modified: 10 Dec 2024

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-12359

    Last Modified: 10 Dec 2024

    A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-12358

    Last Modified: 10 Dec 2024

    A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Dec 2024
    6.9
    Medium

    CVE-2024-12357

    Last Modified: 10 Dec 2024

    A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Dec 2024
    4.2
    Medium

    CVE-2024-12369

    Last Modified: 4 Aug 2026

    A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing attack.

    Published: 9 Dec 2024
    5.7
    Medium

    CVE-2024-55582

    Last Modified: 15 Apr 2026

    Oxide before 6 has unencrypted Control Plane datastores.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-55565

    Last Modified: 15 Apr 2026

    nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-46455

    Last Modified: 15 Apr 2026

    unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

    Published: 9 Dec 2024
    4.8
    Medium

    CVE-2023-43962

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the project settings tab.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2022-29974

    Last Modified: 15 Apr 2026

    AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in certain ASUS devices.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-55578

    Last Modified: 15 Apr 2025

    Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-55580

    Last Modified: 15 Apr 2026

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality risks. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.

    Published: 9 Dec 2024
    8.8
    High

    CVE-2024-55579

    Last Modified: 15 Apr 2026

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.

    Published: 9 Dec 2024
    6.6
    Medium

    CVE-2024-55566

    Last Modified: 15 Apr 2026

    ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54923

    Last Modified: 14 Apr 2025

    A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-54937

    Last Modified: 20 Mar 2025

    A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.

    Published: 9 Dec 2024
    8.8
    High

    CVE-2024-50628

    Last Modified: 27 Jun 2025

    An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve unauthorized manipulation of resources, which may lead to remote code execution when combined with other issues.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-46547

    Last Modified: 15 Apr 2026

    A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2022-38946

    Last Modified: 17 May 2025

    Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2022-38947

    Last Modified: 17 May 2025

    SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-40582

    Last Modified: 17 Apr 2025

    Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

    Published: 9 Dec 2024
    9.1
    Critical

    CVE-2024-40583

    Last Modified: 17 Apr 2025

    Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-48956

    Last Modified: 15 Apr 2026

    Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.

    Published: 9 Dec 2024
    8
    High

    CVE-2024-50625

    Last Modified: 27 Jun 2025

    An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

    Published: 9 Dec 2024
    8.8
    High

    CVE-2024-50626

    Last Modified: 27 Jun 2025

    An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

    Published: 9 Dec 2024
    8.8
    High

    CVE-2024-50627

    Last Modified: 27 Jun 2025

    An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to unauthorized system access.

    Published: 9 Dec 2024
    9.1
    Critical

    CVE-2024-53441

    Last Modified: 15 Apr 2026

    An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-53450

    Last Modified: 10 Jul 2025

    RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54918

    Last Modified: 14 Apr 2025

    Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-54919

    Last Modified: 10 Dec 2024

    A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54920

    Last Modified: 20 Mar 2025

    A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54921

    Last Modified: 14 Apr 2025

    A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.

    Published: 9 Dec 2024
    7.2
    High

    CVE-2024-54922

    Last Modified: 12 Dec 2024

    A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54924

    Last Modified: 14 Apr 2025

    A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54925

    Last Modified: 14 Apr 2025

    A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

    Published: 9 Dec 2024
    8.8
    High

    CVE-2024-54926

    Last Modified: 11 Dec 2024

    A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.

    Published: 9 Dec 2024
    7.2
    High

    CVE-2024-54927

    Last Modified: 24 Apr 2025

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

    Published: 9 Dec 2024