CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2022-31671

    Last Modified: 19 Nov 2024

    Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.

    Published: 14 Nov 2024
    7.7
    High

    CVE-2022-31666

    Last Modified: 12 Jul 2025

    Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-8180

    Last Modified: 13 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.

    Published: 14 Nov 2024
    8.5
    High

    CVE-2024-9693

    Last Modified: 26 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

    Published: 14 Nov 2024
    9.8
    Critical

    CVE-2024-10571

    Last Modified: 8 Apr 2026

    The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-11212

    Last Modified: 19 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Nov 2024
    5.1
    Medium

    CVE-2024-11211

    Last Modified: 6 Jan 2025

    A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-11210

    Last Modified: 19 Nov 2024

    A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-47916

    Last Modified: 15 Apr 2026

    Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-47915

    Last Modified: 15 Apr 2026

    VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    Published: 14 Nov 2024
    4.5
    Medium

    CVE-2024-47914

    Last Modified: 15 Apr 2026

    VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

    Published: 14 Nov 2024
    9.1
    Critical

    CVE-2024-50306

    Last Modified: 3 Nov 2025

    Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-50305

    Last Modified: 4 Jun 2025

    Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-38479

    Last Modified: 3 Nov 2025

    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-45254

    Last Modified: 15 Apr 2026

    VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-45253

    Last Modified: 15 Apr 2026

    Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    Published: 14 Nov 2024
    8.7
    High

    CVE-2024-2550

    Last Modified: 24 Jan 2025

    A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.

    Published: 14 Nov 2024
    4.6
    Medium

    CVE-2024-5920

    Last Modified: 30 Apr 2025

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.

    Published: 14 Nov 2024
    2.1
    Low

    CVE-2024-5917

    Last Modified: 24 Jan 2025

    A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

    Published: 14 Nov 2024
    6.8
    Medium

    CVE-2024-2552

    Last Modified: 24 Jan 2025

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-5918

    Last Modified: 1 Oct 2025

    An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

    Published: 14 Nov 2024
    5.1
    Medium

    CVE-2024-5919

    Last Modified: 24 Jan 2025

    A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.

    Published: 14 Nov 2024
    8.7
    High

    CVE-2024-2551

    Last Modified: 24 Jan 2025

    A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.

    Published: 14 Nov 2024
    8.7
    High

    CVE-2024-9472

    Last Modified: 15 Apr 2026

    A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode. Palo Alto Networks VM-Series, Cloud NGFW, and Prisma Access are not affected. This issue only affects PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series running these specific versions of PAN-OS: * 10.2.7-h12 * 10.2.8-h10 * 10.2.9-h9 * 10.2.9-h11 * 10.2.10-h2 * 10.2.10-h3 * 10.2.11 * 10.2.11-h1 * 10.2.11-h2 * 10.2.11-h3 * 11.1.2-h9 * 11.1.2-h12 * 11.1.3-h2 * 11.1.3-h4 * 11.1.3-h6 * 11.2.2 * 11.2.2-h1

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-11209

    Last Modified: 19 Nov 2024

    A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Nov 2024
    6.3
    Medium

    CVE-2024-11208

    Last Modified: 19 Nov 2024

    A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 14 Nov 2024
    5.1
    Medium

    CVE-2024-7787

    Last Modified: 3 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS, Cross-Site Scripting (XSS). This issue affects vSRM Supplier Relationship Management System: before 28.08.2024.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-11206

    Last Modified: 15 Apr 2026

    Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.

    Published: 14 Nov 2024
    8.6
    High

    CVE-2024-9186

    Last Modified: 15 May 2025

    The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

    Published: 14 Nov 2024
    6.7
    Medium

    CVE-2023-34049

    Last Modified: 15 Apr 2026

    The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. If an attacker has access to the target VM and knows the path to the pre-flight script before it runs they can ensure Salt-SSH runs their script with the privileges of the user running Salt-SSH. Do not make the copy path on the target predictable and ensure we check return codes of the scp command if the copy fails.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-5082

    Last Modified: 15 Apr 2026

    A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-10146

    Last Modified: 15 May 2025

    The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against admins.

    Published: 14 Nov 2024
    5.1
    Medium

    CVE-2024-5083

    Last Modified: 15 Apr 2026

    A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

    Published: 14 Nov 2024
    7
    High

    CVE-2025-5222

    Last Modified: 17 Sept 2026

    A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

    Published: 14 Nov 2024
    5.3
    Medium

    CVE-2024-39707

    Last Modified: 15 Apr 2026

    Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19; kernel 5.4, version 05.46.19; kernel 5.5, version 05.54.19; kernel 5.6, version 05.61.19.

    Published: 14 Nov 2024
    4.9
    Medium

    CVE-2024-11217

    Last Modified: 15 Apr 2026

    A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

    Published: 14 Nov 2024
    8.8
    High

    CVE-2024-41209

    Last Modified: 5 Sept 2025

    A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50829

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

    Published: 14 Nov 2024
    7.2
    High

    CVE-2024-50835

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-50841

    Last Modified: 6 May 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-50968

    Last Modified: 20 Nov 2024

    A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.

    Published: 14 Nov 2024
    9.8
    Critical

    CVE-2024-31695

    Last Modified: 15 Apr 2026

    A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-40579

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the hostname parameter.

    Published: 14 Nov 2024
    6.5
    Medium

    CVE-2024-41206

    Last Modified: 5 Sept 2025

    A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a crafted TS video file.

    Published: 14 Nov 2024
    6.5
    Medium

    CVE-2024-41217

    Last Modified: 5 Sept 2025

    A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted MKV video file.

    Published: 14 Nov 2024
    4.8
    Medium

    CVE-2024-48284

    Last Modified: 19 Nov 2024

    A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request.

    Published: 14 Nov 2024
    6.5
    Medium

    CVE-2024-49776

    Last Modified: 5 Sept 2025

    A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) via a crafted TS video file.

    Published: 14 Nov 2024
    8.8
    High

    CVE-2024-49777

    Last Modified: 5 Sept 2025

    A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information Disclosure and Code Execution via a crafted MKV video file.

    Published: 14 Nov 2024
    8.8
    High

    CVE-2024-49778

    Last Modified: 5 Sept 2025

    A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

    Published: 14 Nov 2024
    9.8
    Critical

    CVE-2024-50823

    Last Modified: 18 Nov 2024

    A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

    Published: 14 Nov 2024