CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-33991

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33990

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33989

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in 'port/event_print.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33988

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/report/attendance_print.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33987

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate', 'events', 'Users' and 'YearLevel' parameters in '/report/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33986

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33985

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33984

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/AttendanceMonitoring/report/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33983

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in '/AttendanceMonitoring/report/attendance_print.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33982

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID' parameter in '/AttendanceMonitoring/student/controller.php'.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-41989

    Last Modified: 4 Nov 2025

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-41990

    Last Modified: 4 Nov 2025

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-41991

    Last Modified: 4 Nov 2025

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

    Published: 6 Aug 2024
    7.3
    High

    CVE-2024-42005

    Last Modified: 4 Nov 2025

    An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-43114

    Last Modified: 11 Sept 2024

    In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

    Published: 6 Aug 2024
    5.1
    Medium

    CVE-2024-7551

    Last Modified: 12 Aug 2024

    A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33974

    Last Modified: 7 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33973

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/report/attendance_print.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33972

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in '/report/event_print.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33971

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in '/login.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33970

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in '/candidate/controller.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33969

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/AttendanceMonitoring/department/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33968

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/AttendanceMonitoring/report/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33967

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in 'Attendance' and 'YearLevel' in '/AttendanceMonitoring/report/attendance_print.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33966

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in '/admin/mod_reports/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33965

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in '/tubigangarden/admin/mod_accomodation/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33964

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_users/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33963

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_room/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33962

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/index.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33961

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33960

    Last Modified: 15 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33959

    Last Modified: 8 Aug 2024

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33981

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33980

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/printreport.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33979

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33958

    Last Modified: 15 Aug 2024

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-33957

    Last Modified: 15 Aug 2024

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33978

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.

    Published: 6 Aug 2024
    6.4
    Medium

    CVE-2024-7317

    Last Modified: 8 Apr 2026

    The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33977

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33976

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in '/admin/user/index.php'.

    Published: 6 Aug 2024
    7.1
    High

    CVE-2024-33975

    Last Modified: 15 Aug 2024

    Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in '/admin/products/index.php'.

    Published: 6 Aug 2024
    7.5
    High

    CVE-2024-41995

    Last Modified: 15 Apr 2026

    Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If this vulnerability is exploited, the product may be affected by some known TLS1.0 and TLS1.1 vulnerabilities. As for the specific products/models/versions of MFPs and printers that contain JavaTM Platform, see the information provided by the vendor.

    Published: 6 Aug 2024
    8.3
    High

    CVE-2024-6203

    Last Modified: 29 Aug 2024

    HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or automatically by an email client software), the password reset token is leaked to the malicious actor, allowing them to set a new password for the victim's account.This potentially leads to account takeover attacks.HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

    Published: 6 Aug 2024
    9.8
    Critical

    CVE-2024-6202

    Last Modified: 29 Aug 2024

    HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

    Published: 6 Aug 2024
    6.9
    Medium

    CVE-2024-7055

    Last Modified: 3 Nov 2025

    A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.

    Published: 6 Aug 2024
    4.8
    Medium

    CVE-2024-7084

    Last Modified: 28 May 2025

    The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-7082

    Last Modified: 28 May 2025

    The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.

    Published: 6 Aug 2024
    5.4
    Medium

    CVE-2024-6766

    Last Modified: 13 Jun 2025

    The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 6 Aug 2024
    6.1
    Medium

    CVE-2024-6651

    Last Modified: 11 Apr 2025

    The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 6 Aug 2024