CVE Feed

    Dashboard / CVE

    9.4
    Critical

    CVE-2024-6235

    Last Modified: 14 May 2025

    Sensitive information disclosure in NetScaler Console

    Published: 10 Jul 2024
    5.4
    Medium

    CVE-2024-27095

    Last Modified: 21 Nov 2024

    Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1.

    Published: 10 Jul 2024
    5.1
    Medium

    CVE-2024-5492

    Last Modified: 25 Jul 2025

    Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

    Published: 10 Jul 2024
    7.2
    High

    CVE-2024-5491

    Last Modified: 25 Jul 2025

    Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

    Published: 10 Jul 2024
    6.1
    Medium

    CVE-2024-5913

    Last Modified: 24 Jan 2025

    An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.

    Published: 10 Jul 2024
    6.8
    Medium

    CVE-2024-5912

    Last Modified: 15 Apr 2026

    An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.

    Published: 10 Jul 2024
    7
    High

    CVE-2024-5911

    Last Modified: 30 Jan 2026

    An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.

    Published: 10 Jul 2024
    9.3
    Critical

    CVE-2024-5910

    Last Modified: 4 Nov 2025

    Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

    Published: 10 Jul 2024
    4.3
    Medium

    CVE-2024-37147

    Last Modified: 7 Jan 2025

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.

    Published: 10 Jul 2024
    6.9
    Medium

    CVE-2024-6649

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the function save_users of the file Users.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271057 was assigned to this vulnerability.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-27090

    Last Modified: 15 Apr 2026

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embbeded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed. This vulnerability is fixed in 0.27.6.

    Published: 10 Jul 2024
    5.1
    Medium

    CVE-2024-6647

    Last Modified: 15 Apr 2026

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file admin/settings/settings/prefix/Theme of the component Setting Handler. The manipulation of the argument Content-Type leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271053 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 10 Jul 2024
    7.5
    High

    CVE-2024-37110

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

    Published: 10 Jul 2024
    9.8
    Critical

    CVE-2024-37113

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

    Published: 10 Jul 2024
    7.5
    High

    CVE-2024-37115

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-37205

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-37270

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-37498

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-37504

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6.

    Published: 10 Jul 2024
    —
    Unknown

    CVE-2024-6664

    Last Modified: 10 Jul 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jul 2024
    —
    Unknown

    CVE-2024-6663

    Last Modified: 10 Jul 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jul 2024
    7.7
    High

    CVE-2024-32759

    Last Modified: 15 Apr 2026

    Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

    Published: 10 Jul 2024
    6.9
    Medium

    CVE-2024-6646

    Last Modified: 15 Apr 2026

    A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Jul 2024
    8.6
    High

    CVE-2024-3325

    Last Modified: 14 Oct 2025

    Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-6645

    Last Modified: 15 Apr 2026

    A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ExpressionUtil.java of the component AviatorScript Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-271051.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-6644

    Last Modified: 15 Apr 2026

    A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java of the component AviatorScript Handler. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-271050 is the identifier assigned to this vulnerability.

    Published: 10 Jul 2024
    9.2
    Critical

    CVE-2024-5217

    Last Modified: 3 Nov 2025

    ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

    Published: 10 Jul 2024
    6.9
    Medium

    CVE-2024-5178

    Last Modified: 15 Apr 2026

    ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

    Published: 10 Jul 2024
    9.3
    Critical

    CVE-2024-4879

    Last Modified: 3 Nov 2025

    ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

    Published: 10 Jul 2024
    6.7
    Medium

    CVE-2024-20456

    Last Modified: 4 Aug 2025

    A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due to an error in the software build process. An attacker could exploit this vulnerability by manipulating the system’s configuration options to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass of the requirement to run Cisco signed images or alter the security properties of the running system.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2023-33860

    Last Modified: 19 May 2025

    IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2023-33859

    Last Modified: 21 Nov 2024

    IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

    Published: 10 Jul 2024
    5.4
    Medium

    CVE-2023-35006

    Last Modified: 15 Sept 2025

    IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

    Published: 10 Jul 2024
    8.8
    High

    CVE-2024-28828

    Last Modified: 21 Nov 2024

    Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.

    Published: 10 Jul 2024
    8.8
    High

    CVE-2024-28827

    Last Modified: 4 Dec 2024

    Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker to gain SYSTEM privileges.

    Published: 10 Jul 2024
    8.7
    High

    CVE-2024-3799

    Last Modified: 15 Apr 2026

    Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause a shell command execution. This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable. Phoniebox in version 3.0 and higher are not affected.

    Published: 10 Jul 2024
    8.7
    High

    CVE-2024-3798

    Last Modified: 15 Apr 2026

    Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause one of the following (depending on the chosen payload): shell command execution, reflected XSS or cross-site request forgery. This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.  Phoniebox in version 3.0 and higher are not affected.

    Published: 10 Jul 2024
    5.3
    Medium

    CVE-2024-6556

    Last Modified: 15 Apr 2026

    The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10.8. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

    Published: 10 Jul 2024
    9.8
    Critical

    CVE-2024-6422

    Last Modified: 21 Nov 2024

    An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

    Published: 10 Jul 2024
    7.5
    High

    CVE-2024-6421

    Last Modified: 22 Aug 2025

    An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

    Published: 10 Jul 2024
    6.4
    Medium

    CVE-2024-5664

    Last Modified: 8 Apr 2026

    The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Jul 2024
    6.1
    Medium

    CVE-2023-6813

    Last Modified: 15 Apr 2026

    The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 10 Jul 2024
    6.1
    Medium

    CVE-2024-36453

    Last Modified: 8 Oct 2025

    Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed.

    Published: 10 Jul 2024
    3.1
    Low

    CVE-2024-36452

    Last Modified: 8 Oct 2025

    Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.

    Published: 10 Jul 2024
    8.8
    High

    CVE-2024-36451

    Last Modified: 8 Oct 2025

    Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted.

    Published: 10 Jul 2024
    5.4
    Medium

    CVE-2024-36450

    Last Modified: 13 Mar 2025

    Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.

    Published: 10 Jul 2024
    8.2
    High

    CVE-2024-39927

    Last Modified: 15 Apr 2026

    Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected products, the products may be able to cause a denial-of-service (DoS) condition and/or user's data may be destroyed.

    Published: 10 Jul 2024
    3.7
    Low

    CVE-2024-39886

    Last Modified: 15 Apr 2026

    TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, a man-in-the-middle attack may allow an attacker to obtain and/or alter communications of the affected App.

    Published: 10 Jul 2024
    —
    Unknown

    CVE-2024-6643

    Last Modified: 11 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Jul 2024
    —
    Unknown

    CVE-2024-6642

    Last Modified: 10 Jul 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Jul 2024