CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2024-6887

    Last Modified: 26 Sept 2024

    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-6019

    Last Modified: 13 Sept 2024

    The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-6018

    Last Modified: 13 Sept 2024

    The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-6017

    Last Modified: 13 Sept 2024

    The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 12 Sept 2024
    4.8
    Medium

    CVE-2024-5799

    Last Modified: 26 Sept 2024

    The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

    Published: 12 Sept 2024
    4.3
    Medium

    CVE-2024-3163

    Last Modified: 26 Sept 2024

    The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

    Published: 12 Sept 2024
    7.5
    High

    CVE-2024-45624

    Last Modified: 15 Apr 2026

    Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved.

    Published: 12 Sept 2024
    6.9
    Medium

    CVE-2024-8711

    Last Modified: 13 Sept 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Sept 2024
    6.5
    Medium

    CVE-2024-38222

    Last Modified: 31 Dec 2024

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-8710

    Last Modified: 13 Sept 2024

    A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of the component Products Table Page. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-8709

    Last Modified: 13 Sept 2024

    A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-8708

    Last Modified: 18 Sept 2024

    A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file categories.php. The manipulation leads to cross site scripting. The attack may be initiated remotely.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32840

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-34783

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    9.8
    Critical

    CVE-2024-29847

    Last Modified: 17 Sept 2024

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-34779

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    8.2
    High

    CVE-2024-37397

    Last Modified: 10 Jul 2025

    An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32848

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-34785

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32843

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32845

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32846

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    7.2
    High

    CVE-2024-32842

    Last Modified: 12 Sept 2024

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-8707

    Last Modified: 15 Apr 2026

    A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/controller/Appadmin.php. The manipulation of the argument url leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Sept 2024
    7.8
    High

    CVE-2024-45181

    Last Modified: 18 Sept 2024

    An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption.

    Published: 12 Sept 2024
    4.3
    Medium

    CVE-2020-24061

    Last Modified: 13 Sept 2024

    Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies via a crafted script

    Published: 12 Sept 2024
    7.5
    High

    CVE-2024-34334

    Last Modified: 18 Sept 2024

    ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.

    Published: 12 Sept 2024
    4.3
    Medium

    CVE-2024-25270

    Last Modified: 25 Mar 2025

    An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.

    Published: 12 Sept 2024
    6.1
    Medium

    CVE-2024-34335

    Last Modified: 18 Sept 2024

    ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-34336

    Last Modified: 18 Sept 2024

    User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.

    Published: 12 Sept 2024
    3.1
    Low

    CVE-2024-36066

    Last Modified: 25 Mar 2025

    The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and only 6 octets long.

    Published: 12 Sept 2024
    5.5
    Medium

    CVE-2024-41629

    Last Modified: 21 Nov 2024

    An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

    Published: 12 Sept 2024
    7.5
    High

    CVE-2024-44459

    Last Modified: 30 Oct 2024

    A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory consumption.

    Published: 12 Sept 2024
    7.5
    High

    CVE-2024-44460

    Last Modified: 30 Oct 2024

    An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

    Published: 12 Sept 2024
    5.5
    Medium

    CVE-2024-45182

    Last Modified: 29 Oct 2024

    An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.

    Published: 12 Sept 2024
    9.1
    Critical

    CVE-2024-40457

    Last Modified: 15 Apr 2026

    No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

    Published: 12 Sept 2024
    5.3
    Medium

    CVE-2024-8706

    Last Modified: 5 Jun 2025

    A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Sept 2024
    8.5
    High

    CVE-2024-28981

    Last Modified: 15 Apr 2026

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

    Published: 11 Sept 2024
    5.4
    Medium

    CVE-2024-7890

    Last Modified: 22 Oct 2024

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

    Published: 11 Sept 2024
    5.3
    Medium

    CVE-2024-8705

    Last Modified: 15 Apr 2026

    A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Sept 2024
    7
    High

    CVE-2024-7889

    Last Modified: 22 Oct 2024

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

    Published: 11 Sept 2024
    5.1
    Medium

    CVE-2024-8694

    Last Modified: 5 Jun 2025

    A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Sept 2024
    5.1
    Medium

    CVE-2024-8693

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component dhcpcd Command Handler. The manipulation of the argument -h with the input <script>alert('XSS')</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Sept 2024
    6.9
    Medium

    CVE-2024-8692

    Last Modified: 3 Oct 2024

    A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Sept 2024
    5.3
    Medium

    CVE-2024-8691

    Last Modified: 1 Nov 2024

    A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.

    Published: 11 Sept 2024
    5.6
    Medium

    CVE-2024-8690

    Last Modified: 15 Oct 2024

    A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

    Published: 11 Sept 2024
    6
    Medium

    CVE-2024-8689

    Last Modified: 15 Apr 2026

    A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles.

    Published: 11 Sept 2024
    6.7
    Medium

    CVE-2024-8688

    Last Modified: 3 Oct 2024

    An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.

    Published: 11 Sept 2024
    6.9
    Medium

    CVE-2024-8687

    Last Modified: 3 Oct 2024

    An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.

    Published: 11 Sept 2024
    8.6
    High

    CVE-2024-20304

    Last Modified: 3 Oct 2024

    A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 code does not properly handle packet memory. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to exhaust the incoming UDP packet memory. The affected device would not be able to process higher-level UDP-based protocols packets, possibly causing a denial of service (DoS) condition. Note: This vulnerability can be exploited using IPv4 or IPv6.

    Published: 11 Sept 2024