CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-2919

    Last Modified: 8 Apr 2026

    The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Sept 2024
    6.4
    Medium

    CVE-2024-8241

    Last Modified: 8 Apr 2026

    The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Sept 2024
    6.4
    Medium

    CVE-2024-8543

    Last Modified: 8 Apr 2026

    The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [sciba] shortcode in all versions up to, and including, 0.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Sept 2024
    2.3
    Low

    CVE-2024-39582

    Last Modified: 31 Dec 2025

    Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 10 Sept 2024
    6.7
    Medium

    CVE-2024-39574

    Last Modified: 16 Sept 2024

    Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

    Published: 10 Sept 2024
    6.7
    Medium

    CVE-2024-39580

    Last Modified: 31 Dec 2025

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 10 Sept 2024
    7.3
    High

    CVE-2024-39581

    Last Modified: 31 Dec 2025

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-39583

    Last Modified: 31 Dec 2025

    Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-43393

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-43392

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-43391

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-43390

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-43389

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43388

    Last Modified: 22 Aug 2025

    A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43387

    Last Modified: 27 Sept 2024

    A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43386

    Last Modified: 27 Sept 2024

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43385

    Last Modified: 27 Sept 2024

    A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-7699

    Last Modified: 27 Sept 2024

    An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

    Published: 10 Sept 2024
    5.7
    Medium

    CVE-2024-7698

    Last Modified: 22 Aug 2025

    A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

    Published: 10 Sept 2024
    2
    Low

    CVE-2024-8258

    Last Modified: 27 Sept 2024

    Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.

    Published: 10 Sept 2024
    3.8
    Low

    CVE-2024-42425

    Last Modified: 16 Sept 2024

    Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 10 Sept 2024
    5.3
    Medium

    CVE-2024-42424

    Last Modified: 20 Dec 2024

    Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 10 Sept 2024
    5.3
    Medium

    CVE-2024-7734

    Last Modified: 28 Sept 2024

    An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-6596

    Last Modified: 1 Oct 2024

    An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

    Published: 10 Sept 2024
    7.6
    High

    CVE-2024-42427

    Last Modified: 20 Dec 2024

    Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 10 Sept 2024
    4.4
    Medium

    CVE-2024-7618

    Last Modified: 8 Apr 2026

    The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 10 Sept 2024
    4.4
    Medium

    CVE-2024-7655

    Last Modified: 8 Apr 2026

    The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 10 Sept 2024
    5.7
    Medium

    CVE-2024-44072

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.

    Published: 10 Sept 2024
    4.8
    Medium

    CVE-2024-7955

    Last Modified: 16 May 2025

    The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 10 Sept 2024
    4.8
    Medium

    CVE-2024-7891

    Last Modified: 16 May 2025

    The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 10 Sept 2024
    6.1
    Medium

    CVE-2024-7784

    Last Modified: 15 Apr 2026

    During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS OS making it vulnerable to a sophisticated attack to bypass this protection. To Axis' knowledge, there are no known exploits of the vulnerability at this time. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 10 Sept 2024
    6.8
    Medium

    CVE-2024-6979

    Last Modified: 14 Jan 2026

    Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts having more privileges than designed. The risk of exploitation is very low as it requires complex steps to execute, including knowing of account passwords and social engineering attacks in tricking the administrator to perform specific configurations on operator- and/or viewer-privileged accounts. Axis has released patched AXIS OS a version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-6173

    Last Modified: 15 Apr 2026

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 10 Sept 2024
    5.9
    Medium

    CVE-2024-21528

    Last Modified: 15 Apr 2026

    All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

    Published: 10 Sept 2024
    5.4
    Medium

    CVE-2024-45285

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module targeting specific parameters, the specific targeted user will no longer have access to any functionality of SAP GUI. There is low impact on integrity and availability of the application.

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-6509

    Last Modified: 15 Apr 2026

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to resource exhaustion of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 10 Sept 2024
    2.4
    Low

    CVE-2024-45284

    Last Modified: 15 Apr 2026

    An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of privileges causing low impact on integrity of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-0067

    Last Modified: 15 Apr 2026

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 10 Sept 2024
    6
    Medium

    CVE-2024-45283

    Last Modified: 15 Apr 2026

    SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-45504

    Last Modified: 15 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.

    Published: 10 Sept 2024
    5.8
    Medium

    CVE-2024-45281

    Last Modified: 28 Oct 2025

    SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.

    Published: 10 Sept 2024
    4.8
    Medium

    CVE-2024-45280

    Last Modified: 15 Apr 2026

    Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.

    Published: 10 Sept 2024
    6.1
    Medium

    CVE-2024-45279

    Last Modified: 15 Apr 2026

    Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-44121

    Last Modified: 15 Apr 2026

    Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application

    Published: 10 Sept 2024
    4.7
    Medium

    CVE-2024-44120

    Last Modified: 15 Apr 2026

    SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser.

    Published: 10 Sept 2024
    5.4
    Medium

    CVE-2024-44117

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-44112

    Last Modified: 16 Sept 2024

    Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.

    Published: 10 Sept 2024
    2.7
    Low

    CVE-2024-41728

    Last Modified: 16 Sept 2024

    Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view these objects.

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-45286

    Last Modified: 15 Apr 2026

    Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.

    Published: 10 Sept 2024
    4.3
    Medium

    CVE-2024-44116

    Last Modified: 15 Apr 2026

    The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on integrity of the application.

    Published: 10 Sept 2024