CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-37409

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beaver Builder: from n/a through <= 1.3.0.4.

    Published: 22 Jul 2024
    5.9
    Medium

    CVE-2024-37414

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.0.2.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-37416

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002.

    Published: 22 Jul 2024
    5.9
    Medium

    CVE-2024-37422

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37428

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.5.0.

    Published: 22 Jul 2024
    5.9
    Medium

    CVE-2024-37429

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.35.

    Published: 22 Jul 2024
    5.9
    Medium

    CVE-2024-37432

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-37433

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.9.

    Published: 22 Jul 2024
    5.9
    Medium

    CVE-2024-37434

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim atarim-visual-collaboration.This issue affects Atarim: from n/a through <= 3.31.

    Published: 22 Jul 2024
    7.1
    High

    CVE-2024-37436

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Reflected XSS.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.

    Published: 22 Jul 2024
    6.5
    Medium

    CVE-2024-37445

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23.

    Published: 22 Jul 2024
    5.4
    Medium

    CVE-2024-6271

    Last Modified: 21 Nov 2024

    The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

    Published: 22 Jul 2024
    8.8
    High

    CVE-2024-6244

    Last Modified: 19 Mar 2025

    The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-6243

    Last Modified: 30 Jan 2026

    The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

    Published: 22 Jul 2024
    8.8
    High

    CVE-2024-5973

    Last Modified: 27 Aug 2025

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-5529

    Last Modified: 18 Mar 2025

    The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-5004

    Last Modified: 21 Nov 2024

    The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-6970

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file /staffcatadd.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272124.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-6969

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ajax/get_patient_history.php. The manipulation of the argument patient_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272123.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-6968

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /print_patients_visits.php. The manipulation of the argument from/to leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272122 is the identifier assigned to this vulnerability.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-6967

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. This affects an unknown part of the file /employee_gatepass/admin/?page=employee/manage_employee. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272121 was assigned to this vulnerability.

    Published: 22 Jul 2024
    6.9
    Medium

    CVE-2024-6966

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php of the component Login. The manipulation of the argument user/pass leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272120.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6965

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical. Affected by this vulnerability is the function fromVirtualSet. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272119. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6964

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. Affected is the function fromDhcpSetSer. The manipulation of the argument dhcpEn/startIP/endIP/preDNS/altDNS/mask/gateway leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272118 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6963

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-41880

    Last Modified: 15 Apr 2026

    In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

    Published: 22 Jul 2024
    4.3
    Medium

    CVE-2024-40075

    Last Modified: 15 Apr 2026

    Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

    Published: 22 Jul 2024
    8.9
    High

    CVE-2024-25638

    Last Modified: 15 Apr 2026

    dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.

    Published: 22 Jul 2024
    8.4
    High

    CVE-2024-34329

    Last Modified: 15 Apr 2026

    Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39250

    Last Modified: 8 Jul 2025

    EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

    Published: 22 Jul 2024
    8.8
    High

    CVE-2024-41320

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.

    Published: 22 Jul 2024
    6.1
    Medium

    CVE-2024-24507

    Last Modified: 13 Mar 2025

    Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-28698

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-37391

    Last Modified: 13 Mar 2025

    ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-38944

    Last Modified: 15 Apr 2026

    An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-40051

    Last Modified: 21 Nov 2024

    IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.

    Published: 22 Jul 2024
    —
    Unknown

    CVE-2024-40430

    Last Modified: 13 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-40502

    Last Modified: 16 May 2025

    SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-40634

    Last Modified: 9 Jan 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.

    Published: 22 Jul 2024
    6.8
    Medium

    CVE-2024-41314

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

    Published: 22 Jul 2024
    6.8
    Medium

    CVE-2024-41315

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41316

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

    Published: 22 Jul 2024
    8
    High

    CVE-2024-41317

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41318

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41703

    Last Modified: 21 Nov 2024

    LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41704

    Last Modified: 21 Nov 2024

    LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-41709

    Last Modified: 21 Mar 2025

    Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

    Published: 22 Jul 2024
    7.6
    High

    CVE-2020-24102

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Punkbuster pbsv.d64 2.351, allows remote attackers to execute arbitrary code.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6962

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Tenda O3 1.0.0.10. This vulnerability affects the function formQosSet. The manipulation of the argument remark/ipRange/upSpeed/downSpeed/enable leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272116. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Jul 2024
    5.9
    Medium

    CVE-2024-37446

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8.

    Published: 21 Jul 2024