CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2023-42949

    Last Modified: 25 Mar 2025

    This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to access edited photos saved to a temporary directory.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2023-40396

    Last Modified: 19 Mar 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2023-42958

    Last Modified: 13 Mar 2025

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.4. An app may be able to gain elevated privileges.

    Published: 29 Jul 2024
    7
    High

    CVE-2023-42959

    Last Modified: 9 Dec 2024

    A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

    Published: 29 Jul 2024
    6.3
    Medium

    CVE-2023-42918

    Last Modified: 9 Dec 2024

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2023-42943

    Last Modified: 15 Mar 2025

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14. An app may be able to read sensitive location information.

    Published: 29 Jul 2024
    3.5
    Low

    CVE-2024-6620

    Last Modified: 15 Apr 2026

    Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398.

    Published: 29 Jul 2024
    5.4
    Medium

    CVE-2024-6578

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab.

    Published: 29 Jul 2024
    5.4
    Medium

    CVE-2024-6727

    Last Modified: 15 Apr 2026

    A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.

    Published: 29 Jul 2024
    8.8
    High

    CVE-2024-6726

    Last Modified: 15 Apr 2026

    Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).

    Published: 29 Jul 2024
    8.3
    High

    CVE-2024-6748

    Last Modified: 15 Apr 2026

    Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.

    Published: 29 Jul 2024
    8.7
    High

    CVE-2024-41819

    Last Modified: 21 Nov 2024

    Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.

    Published: 29 Jul 2024
    6.1
    Medium

    CVE-2024-41810

    Last Modified: 3 Nov 2025

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

    Published: 29 Jul 2024
    8.4
    High

    CVE-2024-41799

    Last Modified: 19 Aug 2025

    tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .dme files could be uploaded via tgstation-server (requiring a separate, isolated privilege) or some other means. A server configured to execute in BYOND's trusted security level (requiring a third separate, isolated privilege OR being set by another user) could lead to this escalating into remote code execution via BYOND's shell() proc. The ability to execute this kind of attack is a known side effect of having privileged TGS users, but normally requires multiple privileges with known weaknesses. This vector is not intentional as it does not require control over the where deployment code is sourced from and _may_ not require remote write access to an instance's `Configuration` directory. This problem is fixed in versions 6.8.0 and above.

    Published: 29 Jul 2024
    4.1
    Medium

    CVE-2024-41676

    Last Modified: 21 Nov 2024

    Magento-lts is a long-term support alternative to Magento Community Edition (CE). This XSS vulnerability affects the design/header/welcome, design/header/logo_src, design/header/logo_src_small, and design/header/logo_alt system configs.They are intended to enable admins to set a text in the two cases, and to define an image url for the other two cases. But because of previously missing escaping allowed to input arbitrary html and as a consequence also arbitrary JavaScript. The problem is patched with Version 20.10.1 or higher.

    Published: 29 Jul 2024
    8.3
    High

    CVE-2024-41671

    Last Modified: 15 Apr 2026

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

    Published: 29 Jul 2024
    9
    Critical

    CVE-2024-38529

    Last Modified: 21 Nov 2024

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to upload a PHP file in the attachment. The uploaded file can be accessed publicly through the URL `{admidio_base_url}/adm_my_files/messages_attachments/{file_name}`. The vulnerability is caused due to the lack of file extension verification, allowing malicious files to be uploaded to the server and public availability of the uploaded file. This vulnerability is fixed in 4.3.10.

    Published: 29 Jul 2024
    9.9
    Critical

    CVE-2024-37906

    Last Modified: 12 Jul 2025

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The SQL Injection results in a compromise of the application's database. The value of `ecard_recipients `POST parameter is being directly concatenated with the SQL query in the source code causing the SQL Injection. The SQL Injection can be exploited by a member user, using blind condition-based, time-based, and Out of band interaction SQL Injection payloads. This vulnerability is fixed in 4.3.9.

    Published: 29 Jul 2024
    8.8
    High

    CVE-2024-6984

    Last Modified: 21 Nov 2024

    An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

    Published: 29 Jul 2024
    7.3
    High

    CVE-2024-6576

    Last Modified: 1 Aug 2025

    Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.

    Published: 29 Jul 2024
    8.5
    High

    CVE-2024-6124

    Last Modified: 23 Feb 2026

    Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7200

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272621 was assigned to this vulnerability.

    Published: 29 Jul 2024
    8.5
    High

    CVE-2024-6881

    Last Modified: 23 Feb 2026

    Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7199

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Complaints Report Management System 1.0. This vulnerability affects unknown code of the file /admin/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272620.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7198

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Complaints Report Management System 1.0. This affects an unknown part of the file /admin/manage_station.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272619.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7197

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/manage_complaint.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272618 is the identifier assigned to this vulnerability.

    Published: 29 Jul 2024
    6.9
    Medium

    CVE-2024-7196

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7195

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Society Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/check_admin.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272616.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7194

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Society Management System 1.0 and classified as critical. This issue affects some unknown processing of the file check_student.php. The manipulation of the argument student_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272615.

    Published: 29 Jul 2024
    4.8
    Medium

    CVE-2024-7193

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.26e is able to address this issue. It is recommended to upgrade the affected component. VDB-272614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7192

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/student.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272613 was assigned to this vulnerability.

    Published: 29 Jul 2024
    7.5
    High

    CVE-2024-41726

    Last Modified: 4 Jun 2025

    Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-41143

    Last Modified: 14 Mar 2025

    Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

    Published: 29 Jul 2024
    7.8
    High

    CVE-2024-41139

    Last Modified: 4 Jun 2025

    Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.

    Published: 29 Jul 2024
    8.8
    High

    CVE-2024-41881

    Last Modified: 15 Apr 2026

    SDoP versions prior to 1.11 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted XML file, arbitrary code may be executed on the user's environment.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7191

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/get_balance.php. The manipulation of the argument student_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272612.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7190

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/get_price.php. The manipulation of the argument expenses_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272611.

    Published: 29 Jul 2024
    5.3
    Medium

    CVE-2024-7189

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272610 is the identifier assigned to this vulnerability.

    Published: 29 Jul 2024
    6.9
    Medium

    CVE-2024-7188

    Last Modified: 21 Nov 2024

    A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272609 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jul 2024
    8.7
    High

    CVE-2024-7187

    Last Modified: 21 Nov 2024

    A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272608. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jul 2024
    8.7
    High

    CVE-2024-7186

    Last Modified: 21 Nov 2024

    A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. This affects the function setWiFiAclAddConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument comment leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272607. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jul 2024
    5.9
    Medium

    CVE-2024-6487

    Last Modified: 30 May 2025

    The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 Jul 2024
    9.1
    Critical

    CVE-2024-6366

    Last Modified: 30 May 2025

    The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

    Published: 29 Jul 2024
    4.6
    Medium

    CVE-2024-6362

    Last Modified: 29 May 2025

    The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 29 Jul 2024
    4.7
    Medium

    CVE-2024-5883

    Last Modified: 10 Apr 2025

    The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 29 Jul 2024
    7.5
    High

    CVE-2024-5882

    Last Modified: 10 Apr 2025

    The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

    Published: 29 Jul 2024
    5.5
    Medium

    CVE-2024-5285

    Last Modified: 7 Jul 2025

    The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

    Published: 29 Jul 2024
    5.4
    Medium

    CVE-2024-4483

    Last Modified: 29 May 2025

    The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

    Published: 29 Jul 2024
    8
    High

    CVE-2024-37381

    Last Modified: 10 Jul 2025

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.

    Published: 29 Jul 2024
    8.7
    High

    CVE-2024-7185

    Last Modified: 21 Nov 2024

    A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument webWlanIdx leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272606 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jul 2024