CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-38808

    Last Modified: 18 Jun 2025

    In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

    Published: 20 Aug 2024
    6.5
    Medium

    CVE-2024-38810

    Last Modified: 28 Feb 2025

    Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

    Published: 20 Aug 2024
    5.4
    Medium

    CVE-2024-39094

    Last Modified: 13 Mar 2025

    Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-42006

    Last Modified: 18 Mar 2025

    Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42607

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

    Published: 20 Aug 2024
    8.6
    High

    CVE-2024-42552

    Last Modified: 5 Jun 2025

    Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42553

    Last Modified: 5 Jun 2025

    A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42586

    Last Modified: 1 May 2025

    A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42559

    Last Modified: 15 Apr 2026

    An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42555

    Last Modified: 5 Jun 2025

    A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42556

    Last Modified: 5 Jun 2025

    Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42557

    Last Modified: 5 Jun 2025

    A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42558

    Last Modified: 5 Jun 2025

    Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42561

    Last Modified: 5 Jun 2025

    Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42563

    Last Modified: 5 Jun 2025

    An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

    Published: 20 Aug 2024
    7.6
    High

    CVE-2024-42564

    Last Modified: 17 Jun 2025

    ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/inventory/delete?action=delete.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42565

    Last Modified: 17 Jun 2025

    ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42566

    Last Modified: 21 Aug 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42568

    Last Modified: 3 Sept 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42569

    Last Modified: 5 Jun 2025

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42570

    Last Modified: 21 Aug 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42571

    Last Modified: 5 Jun 2025

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42572

    Last Modified: 21 Aug 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42574

    Last Modified: 21 Aug 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.

    Published: 20 Aug 2024
    9.8
    Critical

    CVE-2024-42575

    Last Modified: 21 Aug 2024

    School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42576

    Last Modified: 1 May 2025

    A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42577

    Last Modified: 21 Aug 2024

    A Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8
    High

    CVE-2024-42578

    Last Modified: 1 May 2025

    A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42579

    Last Modified: 21 Aug 2024

    A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42606

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42580

    Last Modified: 21 Aug 2024

    A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42582

    Last Modified: 21 Aug 2024

    A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42583

    Last Modified: 21 Aug 2024

    A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42585

    Last Modified: 1 May 2025

    A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

    Published: 20 Aug 2024
    6.7
    Medium

    CVE-2024-42598

    Last Modified: 28 Mar 2025

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42603

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42604

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42605

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42609

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42610

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42611

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42612

    Last Modified: 21 Apr 2025

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42613

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42616

    Last Modified: 26 Mar 2025

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42618

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42619

    Last Modified: 21 Apr 2025

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com

    Published: 20 Aug 2024
    8.8
    High

    CVE-2024-42621

    Last Modified: 21 Aug 2024

    Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

    Published: 20 Aug 2024
    7.5
    High

    CVE-2024-42662

    Last Modified: 14 Mar 2025

    An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.

    Published: 20 Aug 2024
    7.3
    High

    CVE-2024-43688

    Last Modified: 15 Apr 2026

    cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

    Published: 20 Aug 2024
    5.5
    Medium

    CVE-2024-43865

    Last Modified: 10 Oct 2025

    In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception handling for the lfpc instruction within load_fpu_state() was erroneously removed. Add it again to prevent that loading invalid floating point register values cause an unhandled specification exception.

    Published: 20 Aug 2024