CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-6966

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php of the component Login. The manipulation of the argument user/pass leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272120.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6965

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical. Affected by this vulnerability is the function fromVirtualSet. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272119. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6964

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. Affected is the function fromDhcpSetSer. The manipulation of the argument dhcpEn/startIP/endIP/preDNS/altDNS/mask/gateway leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272118 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6963

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Jul 2024
    5.3
    Medium

    CVE-2024-41880

    Last Modified: 15 Apr 2026

    In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

    Published: 22 Jul 2024
    4.3
    Medium

    CVE-2024-40075

    Last Modified: 15 Apr 2026

    Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

    Published: 22 Jul 2024
    8.9
    High

    CVE-2024-25638

    Last Modified: 15 Apr 2026

    dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.

    Published: 22 Jul 2024
    8.4
    High

    CVE-2024-34329

    Last Modified: 15 Apr 2026

    Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-39250

    Last Modified: 8 Jul 2025

    EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

    Published: 22 Jul 2024
    8.8
    High

    CVE-2024-41320

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.

    Published: 22 Jul 2024
    6.1
    Medium

    CVE-2024-24507

    Last Modified: 13 Mar 2025

    Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-28698

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.

    Published: 22 Jul 2024
    7.8
    High

    CVE-2024-37391

    Last Modified: 13 Mar 2025

    ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-38944

    Last Modified: 15 Apr 2026

    An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-40051

    Last Modified: 21 Nov 2024

    IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.

    Published: 22 Jul 2024
    —
    Unknown

    CVE-2024-40430

    Last Modified: 13 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-40502

    Last Modified: 16 May 2025

    SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx

    Published: 22 Jul 2024
    7.5
    High

    CVE-2024-40634

    Last Modified: 9 Jan 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.

    Published: 22 Jul 2024
    6.8
    Medium

    CVE-2024-41314

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

    Published: 22 Jul 2024
    6.8
    Medium

    CVE-2024-41315

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41316

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

    Published: 22 Jul 2024
    8
    High

    CVE-2024-41317

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41318

    Last Modified: 3 Apr 2025

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41703

    Last Modified: 21 Nov 2024

    LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

    Published: 22 Jul 2024
    9.8
    Critical

    CVE-2024-41704

    Last Modified: 21 Nov 2024

    LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

    Published: 22 Jul 2024
    4.8
    Medium

    CVE-2024-41709

    Last Modified: 21 Mar 2025

    Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

    Published: 22 Jul 2024
    7.6
    High

    CVE-2020-24102

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Punkbuster pbsv.d64 2.351, allows remote attackers to execute arbitrary code.

    Published: 22 Jul 2024
    8.7
    High

    CVE-2024-6962

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Tenda O3 1.0.0.10. This vulnerability affects the function formQosSet. The manipulation of the argument remark/ipRange/upSpeed/downSpeed/enable leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272116. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Jul 2024
    5.9
    Medium

    CVE-2024-37446

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8.

    Published: 21 Jul 2024
    5.9
    Medium

    CVE-2024-37447

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager allows Stored XSS.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through 9.6.1.1.

    Published: 21 Jul 2024
    5.9
    Medium

    CVE-2024-37449

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-37457

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: from n/a through 3.1.9.

    Published: 21 Jul 2024
    7.1
    High

    CVE-2024-37459

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a through 6.6.8.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-37460

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SuperSaaS SuperSaaS – online appointment scheduling allows Stored XSS.This issue affects SuperSaaS – online appointment scheduling: from n/a through 2.1.9.

    Published: 21 Jul 2024
    7.1
    High

    CVE-2024-37461

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-37465

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Senol Sahin GPT3 AI Content Writer allows Stored XSS.This issue affects GPT3 AI Content Writer: from n/a through 1.8.66.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-37466

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-37480

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3.

    Published: 21 Jul 2024
    7.1
    High

    CVE-2024-37485

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vinny Alves (UseStrict Consulting) bbPress Notify allows Reflected XSS.This issue affects bbPress Notify: from n/a through 2.18.3.

    Published: 21 Jul 2024
    7.1
    High

    CVE-2024-38781

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Reflected XSS.This issue affects CopySafe Web Protection: from n/a through 3.15.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-38782

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MapsMarker.Com e.U. Leaflet Maps Marker allows Stored XSS.This issue affects Leaflet Maps Marker: from n/a through 3.12.9.

    Published: 21 Jul 2024
    5.9
    Medium

    CVE-2024-38784

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Beaver Builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through 3.6.1.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-38785

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.2.

    Published: 21 Jul 2024
    6.5
    Medium

    CVE-2024-38786

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BurgerThemes CoziPress allows Stored XSS.This issue affects CoziPress: from n/a through 1.0.30.

    Published: 21 Jul 2024
    5.3
    Medium

    CVE-2024-6958

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /st_update.php of the component Avatar File Handler. The manipulation of the argument personal_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272080.

    Published: 21 Jul 2024
    6.9
    Medium

    CVE-2024-6957

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in itsourcecode University Management System 1.0. This affects an unknown part of the file functions.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272079.

    Published: 21 Jul 2024
    5.3
    Medium

    CVE-2024-6956

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode University Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view_cgpa.php. The manipulation of the argument VR/VN leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-272078 is the identifier assigned to this vulnerability.

    Published: 21 Jul 2024
    5.3
    Medium

    CVE-2024-6955

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file sort2.php. The manipulation of the argument qualification leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272076.

    Published: 21 Jul 2024
    5.3
    Medium

    CVE-2024-6954

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file sort1.php. The manipulation of the argument position leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272077 was assigned to this vulnerability.

    Published: 21 Jul 2024
    5.3
    Medium

    CVE-2024-6953

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sms.php. The manipulation of the argument customer leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272075.

    Published: 21 Jul 2024