CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2024-8882

    Last Modified: 14 Nov 2024

    A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.

    Published: 12 Nov 2024
    6.8
    Medium

    CVE-2024-8881

    Last Modified: 14 Nov 2024

    A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.

    Published: 12 Nov 2024
    6.3
    Medium

    CVE-2024-47595

    Last Modified: 14 Nov 2024

    An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.

    Published: 12 Nov 2024
    4.3
    Medium

    CVE-2024-47593

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-47592

    Last Modified: 15 Apr 2026

    SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-47590

    Last Modified: 15 Apr 2026

    An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

    Published: 12 Nov 2024
    4.7
    Medium

    CVE-2024-47588

    Last Modified: 15 Apr 2026

    In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to a high impact on confidentiality, with no impact on integrity or availability.

    Published: 12 Nov 2024
    3.5
    Low

    CVE-2024-47587

    Last Modified: 15 Apr 2026

    Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-47586

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.

    Published: 12 Nov 2024
    6.5
    Medium

    CVE-2024-42372

    Last Modified: 15 Apr 2026

    Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-11102

    Last Modified: 18 Nov 2024

    A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /vm/doctor/edit-doc.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 12 Nov 2024
    5.1
    Medium

    CVE-2024-11101

    Last Modified: 18 Nov 2024

    A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Nov 2024
    5.4
    Medium

    CVE-2021-27703

    Last Modified: 15 Apr 2026

    Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2021-27702

    Last Modified: 15 Apr 2026

    Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.

    Published: 12 Nov 2024
    4.7
    Medium

    CVE-2021-27701

    Last Modified: 15 Apr 2026

    SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF request.

    Published: 12 Nov 2024
    7.6
    High

    CVE-2021-27700

    Last Modified: 15 Apr 2026

    SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard and perform actions like modify user, delete user, etc.

    Published: 12 Nov 2024
    9.1
    Critical

    CVE-2023-52268

    Last Modified: 15 Apr 2026

    The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-48075

    Last Modified: 15 Apr 2026

    A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.

    Published: 12 Nov 2024
    9.8
    Critical

    CVE-2024-43498

    Last Modified: 8 Jul 2025

    .NET and Visual Studio Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.7
    High

    CVE-2024-51093

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.

    Published: 12 Nov 2024
    8
    High

    CVE-2024-51094

    Last Modified: 22 May 2025

    An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing the attacker to exfiltrate internal system data from the CSV file to a remote server.

    Published: 12 Nov 2024
    6.5
    Medium

    CVE-2021-27704

    Last Modified: 27 Jun 2025

    Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

    Published: 12 Nov 2024
    5.4
    Medium

    CVE-2024-28730

    Last Modified: 22 Nov 2024

    Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.

    Published: 12 Nov 2024
    7.5
    High

    CVE-2024-51179

    Last Modified: 29 Sept 2025

    An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

    Published: 12 Nov 2024
    6.6
    Medium

    CVE-2024-28728

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via a crafted payload to the WiFi SSID Name field.

    Published: 12 Nov 2024
    8
    High

    CVE-2024-28726

    Last Modified: 15 Apr 2026

    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.

    Published: 12 Nov 2024
    9.8
    Critical

    CVE-2024-28729

    Last Modified: 22 Nov 2024

    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.

    Published: 12 Nov 2024
    4.3
    Medium

    CVE-2024-28731

    Last Modified: 22 Nov 2024

    Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the Port forwarding option.

    Published: 12 Nov 2024
    7.5
    High

    CVE-2024-43499

    Last Modified: 27 Aug 2025

    .NET and Visual Studio Denial of Service Vulnerability

    Published: 12 Nov 2024
    6.9
    Medium

    CVE-2024-11100

    Last Modified: 18 Nov 2024

    A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    5.8
    Medium

    CVE-2024-23983

    Last Modified: 15 Apr 2026

    Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

    Published: 11 Nov 2024
    6.9
    Medium

    CVE-2024-11099

    Last Modified: 14 Nov 2024

    A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-11097

    Last Modified: 14 Nov 2024

    A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulation leads to infinite loop. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-11096

    Last Modified: 9 Jan 2025

    A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation of the argument projectName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-51484

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that should only be managed by administrators through malicious requests. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-51485

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that should only be managed by administrators through malicious requests. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.5
    Medium

    CVE-2024-51486

    Last Modified: 21 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL - Favicon". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-51487

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating catalog. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that should only be managed by administrators through malicious requests. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-51488

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to delete messages to any user, including administrators, if they interact with a malicious request. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-51489

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another. This vulnerability could be exploited to forge CSRF attacks, allowing an attacker to send messages to any user, including administrators, if they interact with a malicious request. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.5
    Medium

    CVE-2024-51490

    Last Modified: 14 Nov 2024

    Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized, allowing for the input of strings that can execute JavaScript. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    5.3
    Medium

    CVE-2024-11078

    Last Modified: 30 Sept 2025

    A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e/role leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Nov 2024
    9.1
    Critical

    CVE-2024-51747

    Last Modified: 12 Nov 2024

    Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set arbitrary file links, by abusing path traversals. Once the modified db is uploaded and the project page is accessed, a file download can be triggered and all files, readable in the context of the Kanboard application permissions, can be downloaded. This issue has been addressed in version 1.2.42 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    9.1
    Critical

    CVE-2024-51748

    Last Modified: 12 Nov 2024

    Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `settings` table. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, has control over the filepath, which is loaded. Exploiting this vulnerability has one constraint: the attacker must be able to place a file (called translations.php) on the system. However, this is not impossible, think of anonymous FTP server or another application that allows uploading files. Once the attacker has placed its file with the actual php code as the payload, the attacker can craft a sqlite db settings, which uses path traversal to point to the directory, where the `translations.php` file is stored. Then gaining code execution after importing the crafted sqlite.db. This issue has been addressed in version 1.2.42 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    4.1
    Medium

    CVE-2024-51992

    Last Modified: 15 Apr 2026

    Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue (CWE-749: Exposed Dangerous Method or Function) in the Orchid Platform’s asynchronous modal functionality, affecting users of Orchid Platform version 8 through 14.42.x. Attackers could exploit this vulnerability to call arbitrary methods within the `Screen` class, leading to potential brute force of database tables, validation checks against user credentials, and disclosure of the server’s real IP address. The issue has been patched in the latest release, version 14.43.0, released on November 6, 2024. Users should upgrade to version 14.43.0 or later to address this vulnerability. If upgrading to version 14.43.0 is not immediately possible, users can mitigate the vulnerability by implementing middleware to intercept and validate requests to asynchronous modal endpoints, allowing only approved methods and parameters.

    Published: 11 Nov 2024
    2
    Low

    CVE-2024-52286

    Last Modified: 15 Apr 2026

    Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted user input (file name) and uses it directly in the creation of HTML pages allowing any unauthenticated to execute JavaScript code in the context of the user. The issue stems to the code starting at `Line 24` in `src/main/resources/static/js/merge.js`. The file name is directly being input into InnerHTML with no sanitization on the file name, allowing a malicious user to be able to upload files with names containing HTML tags. As HTML tags can include JavaScript code, this can be used to execute JavaScript code in the context of the user. This is a self-injection style attack and relies on a user uploading the malicious file themselves and it impact only them, not other users. A user might be social engineered into running this to launch a phishing attack. Nevertheless, this breaks the expected security restrictions in place by the application. This issue has been addressed in version 0.32.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    6.9
    Medium

    CVE-2024-10315

    Last Modified: 15 Apr 2026

    In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.

    Published: 11 Nov 2024
    5.1
    Medium

    CVE-2024-52288

    Last Modified: 15 Apr 2026

    libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In affected versions an unexpected `REPLY_CCRYPT` or `REPLY_RMAC_I` may be introduced into an active stream when they should not be. Once RMAC_I message can be sent during a session, attacker with MITM access to the communication may intercept the original RMAC_I reply and save it. While the session continues, the attacker will record all of the replies and save them, till capturing the message to be replied (can be detected by ID, length or time based on inspection of visual activity next to the reader) Once attacker captures a session with the message to be replayed, he stops resetting the connection and waits for signal to perform the replay to of the PD to CP message (ex: by signaling remotely to the MIMT device or setting a specific timing). In order to replay, the attacker will craft a specific RMAC_I message in the proper seq of the execution, which will result in reverting the RMAC to the beginning of the session. At that phase - attacker can replay all the messages from the beginning of the session. This issue has been addressed in commit `298576d9` which is included in release version 3.0.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 11 Nov 2024
    4.8
    Medium

    CVE-2024-45087

    Last Modified: 18 Nov 2024

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 11 Nov 2024
    —
    Unknown

    CVE-2024-11105

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Nov 2024