CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-28972

    Last Modified: 3 Sept 2024

    Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure.

    Published: 1 Aug 2024
    4.8
    Medium

    CVE-2024-38481

    Last Modified: 2 Aug 2024

    Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

    Published: 1 Aug 2024
    5.8
    Medium

    CVE-2024-38490

    Last Modified: 2 Aug 2024

    Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

    Published: 1 Aug 2024
    3.1
    Low

    CVE-2024-38489

    Last Modified: 2 Aug 2024

    Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.

    Published: 1 Aug 2024
    4.8
    Medium

    CVE-2024-25948

    Last Modified: 2 Aug 2024

    Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

    Published: 1 Aug 2024
    4.8
    Medium

    CVE-2024-25947

    Last Modified: 2 Aug 2024

    Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

    Published: 1 Aug 2024
    4.7
    Medium

    CVE-2024-5678

    Last Modified: 15 Aug 2024

    Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

    Published: 1 Aug 2024
    4.3
    Medium

    CVE-2024-5331

    Last Modified: 8 Apr 2026

    The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

    Published: 1 Aug 2024
    6.4
    Medium

    CVE-2024-5330

    Last Modified: 8 Apr 2026

    The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Aug 2024
    6.4
    Medium

    CVE-2024-7302

    Last Modified: 8 Apr 2026

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.

    Published: 1 Aug 2024
    7.1
    High

    CVE-2024-6529

    Last Modified: 10 Apr 2025

    The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-6496

    Last Modified: 9 Jun 2025

    The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack

    Published: 1 Aug 2024
    4.8
    Medium

    CVE-2024-4090

    Last Modified: 10 Jun 2025

    The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 1 Aug 2024
    8.1
    High

    CVE-2024-3983

    Last Modified: 29 May 2025

    The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

    Published: 1 Aug 2024
    4.8
    Medium

    CVE-2024-2872

    Last Modified: 16 Jul 2025

    The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-2843

    Last Modified: 29 May 2025

    The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-7343

    Last Modified: 15 Aug 2024

    A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273274 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-7342

    Last Modified: 15 Aug 2024

    A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273273 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    6.4
    Medium

    CVE-2024-2090

    Last Modified: 8 Apr 2026

    The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 1 Aug 2024
    6.9
    Medium

    CVE-2024-7339

    Last Modified: 20 Dec 2024

    A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7338

    Last Modified: 9 Aug 2024

    A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273261 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.8
    High

    CVE-2024-6698

    Last Modified: 8 Apr 2026

    The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7337

    Last Modified: 9 Aug 2024

    A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7336

    Last Modified: 9 Aug 2024

    A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7335

    Last Modified: 9 Aug 2024

    A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273258 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    6.5
    Medium

    CVE-2024-1747

    Last Modified: 29 May 2025

    The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-6687

    Last Modified: 8 Apr 2026

    The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names, phone numbers, physical addresses, and email addresses

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7334

    Last Modified: 9 Aug 2024

    A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273257 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.8
    High

    CVE-2024-40883

    Last Modified: 17 Feb 2025

    Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.

    Published: 1 Aug 2024
    6.8
    Medium

    CVE-2024-39607

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.

    Published: 1 Aug 2024
    6.8
    Medium

    CVE-2024-34021

    Last Modified: 15 Apr 2026

    Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7333

    Last Modified: 9 Aug 2024

    A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273256. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    9.3
    Critical

    CVE-2024-7332

    Last Modified: 9 Aug 2024

    A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    8.7
    High

    CVE-2024-7331

    Last Modified: 1 Aug 2024

    A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Aug 2024
    5.5
    Medium

    CVE-2024-6923

    Last Modified: 15 Apr 2026

    There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

    Published: 1 Aug 2024
    7.5
    High

    CVE-2024-41260

    Last Modified: 15 Apr 2026

    A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-41946

    Last Modified: 3 Nov 2025

    REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.

    Published: 1 Aug 2024
    7.5
    High

    CVE-2024-41264

    Last Modified: 16 Aug 2024

    An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

    Published: 1 Aug 2024
    5.3
    Medium

    CVE-2024-41123

    Last Modified: 3 Nov 2025

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.

    Published: 1 Aug 2024
    9.1
    Critical

    CVE-2024-41259

    Last Modified: 26 Aug 2025

    Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.

    Published: 1 Aug 2024
    7.5
    High

    CVE-2024-41265

    Last Modified: 15 Apr 2026

    A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.

    Published: 1 Aug 2024
    —
    Unknown

    CVE-2024-1715

    Last Modified: 2 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34802. Reason: This candidate is a duplicate of CVE-2024-34802. Notes: All CVE users should reference CVE-2024-34802 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7330

    Last Modified: 23 Aug 2024

    A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    9
    Critical

    CVE-2024-38182

    Last Modified: 10 Feb 2026

    Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7329

    Last Modified: 23 Aug 2024

    A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the argument files leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273252. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7328

    Last Modified: 23 Aug 2024

    A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?action=phpinfo. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7327

    Last Modified: 23 Aug 2024

    A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php. The manipulation of the argument nickName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273250 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    8.5
    High

    CVE-2024-7326

    Last Modified: 15 Aug 2024

    A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2024
    5.5
    Medium

    CVE-2017-3772

    Last Modified: 13 Aug 2024

    A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

    Published: 31 Jul 2024
    7.8
    High

    CVE-2019-6197

    Last Modified: 13 Aug 2024

    A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

    Published: 31 Jul 2024