CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2024-38890

    Last Modified: 6 May 2025

    An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-41517

    Last Modified: 28 Oct 2024

    An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.2.3 allows remote attackers to get a list of all users and their corresponding privileges.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-41518

    Last Modified: 3 Sept 2024

    An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.

    Published: 2 Aug 2024
    5.4
    Medium

    CVE-2024-41519

    Last Modified: 29 Oct 2024

    Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltungen/<event_id>" through the "school" input field.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-42458

    Last Modified: 5 Sept 2024

    server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.

    Published: 2 Aug 2024
    9.1
    Critical

    CVE-2024-42461

    Last Modified: 3 Nov 2025

    In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

    Published: 2 Aug 2024
    6.1
    Medium

    CVE-2024-33893

    Last Modified: 4 Nov 2025

    Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-38889

    Last Modified: 20 Feb 2026

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

    Published: 2 Aug 2024
    7.5
    High

    CVE-2024-38881

    Last Modified: 24 Feb 2026

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.

    Published: 2 Aug 2024
    9.8
    Critical

    CVE-2024-38882

    Last Modified: 24 Feb 2026

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

    Published: 2 Aug 2024
    5.3
    Medium

    CVE-2024-7372

    Last Modified: 7 Aug 2024

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /quiz_board.php. The manipulation of the argument quiz leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273356.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-7371

    Last Modified: 7 Aug 2024

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /quiz_view.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273355.

    Published: 1 Aug 2024
    5.9
    Medium

    CVE-2024-39626

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugins Pretty Simple Popup Builder pretty-simple-popup-builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through <= 1.0.9.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-7370

    Last Modified: 7 Aug 2024

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_quiz.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273354 is the identifier assigned to this vulnerability.

    Published: 1 Aug 2024
    5.9
    Medium

    CVE-2024-39627

    Last Modified: 11 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3.

    Published: 1 Aug 2024
    5.9
    Medium

    CVE-2024-39629

    Last Modified: 11 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39631

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

    Published: 1 Aug 2024
    5.8
    Medium

    CVE-2024-39643

    Last Modified: 11 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagic allows Stored XSS.This issue affects RegistrationMagic: from n/a through 6.0.0.1.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39644

    Last Modified: 11 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39646

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39647

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.1.1.

    Published: 1 Aug 2024
    8.1
    High

    CVE-2024-41956

    Last Modified: 15 Apr 2026

    Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve passes all environment variables given by the client to git subprocesses. This includes environment variables that control program execution, such as LD_PRELOAD. This vulnerability is fixed in 0.7.5.

    Published: 1 Aug 2024
    3
    Low

    CVE-2024-41948

    Last Modified: 9 Aug 2024

    biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to generate a third-party block and to sign it, which includes the public key of the previous block (used in the signature) and the public keys part of the token symbol table (for public key interning in datalog expressions). A third-part block request forged by a malicious user can trick the third-party authority into generating datalog trusting the wrong keypair. This vulnerability is fixed in 4.0.0.

    Published: 1 Aug 2024
    3
    Low

    CVE-2024-41949

    Last Modified: 9 Aug 2024

    biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to generate a third-party block and to sign it, which includes the public key of the previous block (used in the signature) and the public keys part of the token symbol table (for public key interning in datalog expressions). A third-part block request forged by a malicious user can trick the third-party authority into generating datalog trusting the wrong keypair.

    Published: 1 Aug 2024
    6.9
    Medium

    CVE-2024-7369

    Last Modified: 7 Aug 2024

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273353 was assigned to this vulnerability.

    Published: 1 Aug 2024
    6.8
    Medium

    CVE-2024-32862

    Last Modified: 9 Aug 2024

    Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

    Published: 1 Aug 2024
    5.9
    Medium

    CVE-2024-39648

    Last Modified: 11 Aug 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39649

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite.This issue affects Essential Addons for Elementor: from n/a through <= 5.9.26.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39652

    Last Modified: 28 Jan 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.

    Published: 1 Aug 2024
    9
    Critical

    CVE-2024-32758

    Last Modified: 9 Aug 2024

    Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39655

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.77.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39656

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39659

    Last Modified: 31 Mar 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affects WP-PostRatings: from n/a through 1.91.1.

    Published: 1 Aug 2024
    4.2
    Medium

    CVE-2024-41965

    Last Modified: 17 Sept 2026

    Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.

    Published: 1 Aug 2024
    5.9
    Medium

    CVE-2024-39660

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39661

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39662

    Last Modified: 21 Mar 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-39663

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39665

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter & Grids allows Stored XSS.This issue affects Filter & Grids: from n/a through 2.9.2.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39667

    Last Modified: 22 Jan 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.6.11.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-39668

    Last Modified: 22 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Stored XSS.This issue affects Extensions for Elementor: from n/a through 2.0.31.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-7368

    Last Modified: 7 Aug 2024

    A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273352.

    Published: 1 Aug 2024
    7.5
    High

    CVE-2024-38761

    Last Modified: 11 Feb 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.

    Published: 1 Aug 2024
    8.3
    High

    CVE-2024-39636

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.

    Published: 1 Aug 2024
    5.4
    Medium

    CVE-2024-39637

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0.

    Published: 1 Aug 2024
    5.7
    Medium

    CVE-2024-32931

    Last Modified: 9 Aug 2024

    Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

    Published: 1 Aug 2024
    6.4
    Medium

    CVE-2024-32865

    Last Modified: 9 Aug 2024

    Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

    Published: 1 Aug 2024
    6.4
    Medium

    CVE-2024-32864

    Last Modified: 9 Aug 2024

    Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

    Published: 1 Aug 2024
    9.4
    Critical

    CVE-2024-7093

    Last Modified: 15 Apr 2026

    Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.

    Published: 1 Aug 2024
    8
    High

    CVE-2023-52209

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.

    Published: 1 Aug 2024