CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-7307

    Last Modified: 13 Aug 2024

    A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_billing.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273199.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-2508

    Last Modified: 15 Apr 2026

    The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up to, and including, 2.8.4.4. This makes it possible for unauthenticated attackers to add the '_mobmenu_icon' post meta to arbitrary posts with an arbitrary (but sanitized) value. NOTE: Version 2.8.4.4 contains a partial fix for this vulnerability.

    Published: 31 Jul 2024
    7.8
    High

    CVE-2024-37127

    Last Modified: 27 Aug 2024

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

    Published: 31 Jul 2024
    7.3
    High

    CVE-2024-37142

    Last Modified: 8 Aug 2024

    Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7306

    Last Modified: 12 Aug 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Establishment Billing Management System 1.0. Affected is an unknown function of the file /manage_block.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273198 is the identifier assigned to this vulnerability.

    Published: 31 Jul 2024
    6.2
    Medium

    CVE-2023-28074

    Last Modified: 20 Aug 2024

    Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7303

    Last Modified: 12 Aug 2024

    A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /request.php of the component Send Blood Request Page. The manipulation of the argument Address/bloodgroup leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273185 was assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7300

    Last Modified: 13 Feb 2025

    A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

    Published: 31 Jul 2024
    9.2
    Critical

    CVE-2024-6980

    Last Modified: 7 Feb 2025

    A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7299

    Last Modified: 13 Feb 2025

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing of the file /preview/page of the component Entry Preview Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273167. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7290

    Last Modified: 13 Aug 2024

    A vulnerability classified as critical has been found in SourceCodester Establishment Billing Management System 1.0. This affects an unknown part of the file /manage_tenant.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273159.

    Published: 31 Jul 2024
    9.8
    Critical

    CVE-2024-6695

    Last Modified: 2 Jan 2026

    it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-6412

    Last Modified: 30 Jan 2026

    The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 31 Jul 2024
    5.4
    Medium

    CVE-2024-6408

    Last Modified: 6 May 2025

    The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 31 Jul 2024
    6.1
    Medium

    CVE-2024-6272

    Last Modified: 10 Jun 2025

    The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 31 Jul 2024
    4.8
    Medium

    CVE-2024-6165

    Last Modified: 7 Jul 2025

    The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 31 Jul 2024
    9.4
    Critical

    CVE-2024-7205

    Last Modified: 15 Apr 2026

    When the device is shared, the homepage module are before 2.19.0  in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7289

    Last Modified: 13 Aug 2024

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_payment.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273158 is the identifier assigned to this vulnerability.

    Published: 31 Jul 2024
    7.2
    High

    CVE-2024-6770

    Last Modified: 15 Apr 2026

    The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7288

    Last Modified: 12 Aug 2024

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_block. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273157 was assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7287

    Last Modified: 12 Aug 2024

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273156.

    Published: 31 Jul 2024
    5
    Medium

    CVE-2024-7319

    Last Modified: 20 Nov 2025

    An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7286

    Last Modified: 12 Aug 2024

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273155.

    Published: 31 Jul 2024
    8.6
    High

    CVE-2024-39950

    Last Modified: 30 Sept 2025

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-39949

    Last Modified: 30 Sept 2025

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-39948

    Last Modified: 30 Sept 2025

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7285

    Last Modified: 12 Aug 2024

    A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273154 is the identifier assigned to this vulnerability.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-39947

    Last Modified: 27 Oct 2024

    A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

    Published: 31 Jul 2024
    6
    Medium

    CVE-2024-39946

    Last Modified: 27 Oct 2024

    A vulnerability has been found in Dahua products.After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing device initialization.

    Published: 31 Jul 2024
    4.9
    Medium

    CVE-2024-39945

    Last Modified: 27 Mar 2025

    A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-39944

    Last Modified: 30 Sept 2025

    A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7284

    Last Modified: 8 Aug 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_settings. The manipulation of the argument about leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273153 was assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7283

    Last Modified: 8 Aug 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Lot Reservation Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273152.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7282

    Last Modified: 8 Aug 2024

    A vulnerability classified as critical was found in SourceCodester Lot Reservation Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/manage_model.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273151.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7281

    Last Modified: 8 Aug 2024

    A vulnerability classified as critical has been found in SourceCodester Lot Reservation Management System 1.0. Affected is an unknown function of the file /admin/index.php?page=manage_lot. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273150 is the identifier assigned to this vulnerability.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-7280

    Last Modified: 8 Aug 2024

    A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/view_reserved.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273149 was assigned to this vulnerability.

    Published: 31 Jul 2024
    6.9
    Medium

    CVE-2024-7279

    Last Modified: 8 Aug 2024

    A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273148.

    Published: 31 Jul 2024
    8.2
    High

    CVE-2024-6255

    Last Modified: 21 Nov 2024

    A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation of file paths, enabling directory traversal attacks. An attacker can exploit this vulnerability to disrupt the functioning of the system, manipulate settings, or potentially cause data loss or corruption.

    Published: 31 Jul 2024
    5.1
    Medium

    CVE-2024-7278

    Last Modified: 14 May 2025

    A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_save.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273147.

    Published: 31 Jul 2024
    7.1
    High

    CVE-2024-41253

    Last Modified: 15 Apr 2026

    goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

    Published: 31 Jul 2024
    6.1
    Medium

    CVE-2023-28149

    Last Modified: 15 Apr 2026

    An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-40465

    Last Modified: 15 Aug 2024

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file

    Published: 31 Jul 2024
    7.6
    High

    CVE-2024-41630

    Last Modified: 7 Apr 2025

    Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

    Published: 31 Jul 2024
    7.5
    High

    CVE-2024-41255

    Last Modified: 29 Sept 2025

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

    Published: 31 Jul 2024
    6.5
    Medium

    CVE-2024-7264

    Last Modified: 3 Nov 2025

    libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

    Published: 31 Jul 2024
    8.8
    High

    CVE-2024-40464

    Last Modified: 15 Aug 2024

    An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-41254

    Last Modified: 29 Oct 2024

    An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

    Published: 31 Jul 2024
    5.9
    Medium

    CVE-2024-41256

    Last Modified: 18 Mar 2025

    Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.

    Published: 31 Jul 2024
    5.3
    Medium

    CVE-2024-41258

    Last Modified: 13 Mar 2025

    An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.

    Published: 31 Jul 2024
    7.4
    High

    CVE-2024-41262

    Last Modified: 10 Jul 2025

    mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.

    Published: 31 Jul 2024