CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-8301

    Last Modified: 30 Aug 2024

    A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax/checkin.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Aug 2024
    6.9
    Medium

    CVE-2024-8297

    Last Modified: 30 Aug 2024

    A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is possible to launch the attack remotely. The name of the patch is 81b3336b4c9240f0bf50c13cb8375cf860d945f1. It is recommended to apply a patch to fix this issue.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-3679

    Last Modified: 8 Apr 2026

    The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.002. This makes it possible for unauthenticated attackers to view limited information from password protected posts through the social meta data.

    Published: 29 Aug 2024
    6.4
    Medium

    CVE-2024-1384

    Last Modified: 8 Apr 2026

    The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-8296

    Last Modified: 30 Aug 2024

    A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument User[avatar] leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-2541

    Last Modified: 8 Apr 2026

    The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This data may include the first name, last name, e-mail address, and potentially other personally identifiable information of subscribers.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-8295

    Last Modified: 30 Aug 2024

    A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The manipulation of the argument BannerForm[img] leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-8294

    Last Modified: 30 Aug 2024

    A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument FriendlyLink[image] leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Aug 2024
    6.4
    Medium

    CVE-2024-7895

    Last Modified: 8 Apr 2026

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.8.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-6551

    Last Modified: 8 Apr 2026

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29723

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categoria;.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29724

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter idDesafio.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29725

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29726

    Last Modified: 6 Sept 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/, parameter id.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29727

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter send.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29728

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ , parameter idDesafio.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29729

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/, parameter url.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29730

    Last Modified: 6 Sept 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ , parameter idCat;.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-29731

    Last Modified: 30 Aug 2024

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/ , parameters idChallenge and idEmpresa.

    Published: 29 Aug 2024
    5.9
    Medium

    CVE-2024-43986

    Last Modified: 4 Oct 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: through 1.0.9.

    Published: 29 Aug 2024
    5.1
    Medium

    CVE-2024-5624

    Last Modified: 13 Sept 2024

    Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-5623

    Last Modified: 13 Sept 2024

    An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.

    Published: 29 Aug 2024
    7.3
    High

    CVE-2024-5622

    Last Modified: 13 Sept 2024

    An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.

    Published: 29 Aug 2024
    3.8
    Low

    CVE-2024-38304

    Last Modified: 20 Dec 2024

    Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 29 Aug 2024
    6.9
    Medium

    CVE-2024-4428

    Last Modified: 3 Jun 2026

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.

    Published: 29 Aug 2024
    7.8
    High

    CVE-2024-43700

    Last Modified: 30 Nov 2024

    xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, arbitrary code may be executed on the user's environment.

    Published: 29 Aug 2024
    4.8
    Medium

    CVE-2024-7132

    Last Modified: 7 Oct 2024

    The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 Aug 2024
    4.8
    Medium

    CVE-2024-6927

    Last Modified: 7 Oct 2024

    The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-5417

    Last Modified: 7 Oct 2024

    The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 29 Aug 2024
    8.8
    High

    CVE-2024-7607

    Last Modified: 8 Apr 2026

    The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-5987

    Last Modified: 8 Apr 2026

    The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit or delete contrast settings. Please note these issues were patched in 0.6.2.8, though it broke functionality and the vendor has not responded to our follow-ups.

    Published: 29 Aug 2024
    4.4
    Medium

    CVE-2024-3944

    Last Modified: 8 Apr 2026

    The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 29 Aug 2024
    6.4
    Medium

    CVE-2024-7606

    Last Modified: 8 Apr 2026

    The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, 3.2.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-38303

    Last Modified: 20 Dec 2024

    Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 29 Aug 2024
    4.3
    Medium

    CVE-2024-7418

    Last Modified: 8 Apr 2026

    The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).

    Published: 29 Aug 2024
    8.1
    High

    CVE-2024-7856

    Last Modified: 8 Apr 2026

    The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.

    Published: 29 Aug 2024
    7.2
    High

    CVE-2022-2440

    Last Modified: 8 Apr 2026

    The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-5857

    Last Modified: 8 Apr 2026

    The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to delete arbitrary media files.

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41918

    Last Modified: 30 Aug 2024

    'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.

    Published: 29 Aug 2024
    6.5
    Medium

    CVE-2024-7857

    Last Modified: 8 Apr 2026

    The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-41361

    Last Modified: 4 Sept 2024

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-41372

    Last Modified: 4 Sept 2024

    Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.

    Published: 29 Aug 2024
    5.3
    Medium

    CVE-2024-45440

    Last Modified: 21 Apr 2025

    core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41347

    Last Modified: 26 Jan 2026

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41348

    Last Modified: 26 Jan 2026

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41358

    Last Modified: 26 Jan 2026

    phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41349

    Last Modified: 26 Jan 2026

    unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-41346

    Last Modified: 26 Jan 2026

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-41345

    Last Modified: 26 Jan 2026

    openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-41350

    Last Modified: 4 Sept 2024

    bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php

    Published: 29 Aug 2024