CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-28749

    Last Modified: 15 Apr 2026

    A remote attacker with high privileges may use a writing file function to inject OS commands.

    Published: 9 Jul 2024
    7.2
    High

    CVE-2024-28748

    Last Modified: 15 Apr 2026

    A remote attacker with high privileges may use a reading file function to inject OS commands.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-28747

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

    Published: 9 Jul 2024
    6.3
    Medium

    CVE-2024-22062

    Last Modified: 28 Jan 2025

    There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-6334

    Last Modified: 21 May 2025

    The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

    Published: 9 Jul 2024
    4.8
    Medium

    CVE-2024-5802

    Last Modified: 13 Mar 2025

    The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-5488

    Last Modified: 21 May 2025

    The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-3410

    Last Modified: 21 May 2025

    The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-5441

    Last Modified: 8 Apr 2026

    The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all versions up to, and including, 7.11.0. This makes it possible for authenticated attackers, with subscriber access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The plugin allows administrators (via its settings) to extend the ability to submit events to unauthenticated users, which would allow unauthenticated attackers to exploit this vulnerability.

    Published: 9 Jul 2024
    3.3
    Low

    CVE-2024-34692

    Last Modified: 21 Nov 2024

    Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker can cause limited impact on confidentiality and Integrity of the application.

    Published: 9 Jul 2024
    4.1
    Medium

    CVE-2024-37180

    Last Modified: 29 Oct 2025

    Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.

    Published: 9 Jul 2024
    6.4
    Medium

    CVE-2024-6169

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jul 2024
    6.4
    Medium

    CVE-2024-6170

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jul 2024
    6.4
    Medium

    CVE-2024-4667

    Last Modified: 8 Apr 2026

    The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post and Category Filter widget in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied 'post_types' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-6166

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above and granted plugin setting edit permissions by an administrator, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-6171

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-39596

    Last Modified: 15 Apr 2026

    Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.

    Published: 9 Jul 2024
    4.7
    Medium

    CVE-2024-39599

    Last Modified: 28 Oct 2025

    Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidentiality, integrity, and availability.

    Published: 9 Jul 2024
    5
    Medium

    CVE-2024-37171

    Last Modified: 21 Nov 2024

    SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.

    Published: 9 Jul 2024
    5
    Medium

    CVE-2024-39600

    Last Modified: 22 Jan 2025

    Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the confidentiality but there is no impact on the integrity and availability.

    Published: 9 Jul 2024
    5
    Medium

    CVE-2024-34689

    Last Modified: 21 Nov 2024

    WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.

    Published: 9 Jul 2024
    5.4
    Medium

    CVE-2024-37172

    Last Modified: 21 Nov 2024

    SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.

    Published: 9 Jul 2024
    5.4
    Medium

    CVE-2024-39595

    Last Modified: 28 Oct 2025

    SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-39594

    Last Modified: 29 Oct 2025

    SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-37175

    Last Modified: 21 Nov 2024

    SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.

    Published: 9 Jul 2024
    5
    Medium

    CVE-2024-39598

    Last Modified: 21 Nov 2024

    SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-37174

    Last Modified: 21 Nov 2024

    Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-37173

    Last Modified: 21 Nov 2024

    Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-34685

    Last Modified: 21 Nov 2024

    Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity.

    Published: 9 Jul 2024
    6.9
    Medium

    CVE-2024-39593

    Last Modified: 21 Nov 2024

    SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.

    Published: 9 Jul 2024
    7.2
    High

    CVE-2024-39597

    Last Modified: 15 Apr 2026

    In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehand. If the site is not configured as isolated site, this can also grant access to other non-isolated early login sites, even if registration is not enabled for those other sites.

    Published: 9 Jul 2024
    7.7
    High

    CVE-2024-39592

    Last Modified: 21 Nov 2024

    Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-6365

    Last Modified: 15 Apr 2026

    The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php file. This makes it possible for unauthenticated attackers to execute code on the server.

    Published: 9 Jul 2024
    8.6
    High

    CVE-2024-5974

    Last Modified: 7 Aug 2026

    A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

    Published: 9 Jul 2024
    8.6
    High

    CVE-2024-4944

    Last Modified: 7 Aug 2026

    A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-5793

    Last Modified: 15 Apr 2026

    The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-5855

    Last Modified: 15 Apr 2026

    The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the bulk_action_delete and delete_single_image_call AJAX actions in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary attachments. A nonce check was added in version 3.0.1, however, it wasn't until version 3.0.2 that a capability check was added.

    Published: 9 Jul 2024
    4.8
    Medium

    CVE-2024-34786

    Last Modified: 15 Apr 2026

    UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2024-5549

    Last Modified: 15 Jul 2025

    A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability also enables attackers to perform actions on behalf of the user, such as deleting projects or sending messages. The issue arises from the lack of proper origin validation, allowing unauthorized cross-origin requests to be executed. The vulnerability is present in all versions of the repository, as no fixed version has been specified.

    Published: 9 Jul 2024
    10
    Critical

    CVE-2024-6886

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

    Published: 9 Jul 2024
    6.2
    Medium

    CVE-2024-5569

    Last Modified: 15 Apr 2026

    A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the `Path` module in both zipp and zipfile, such as `joinpath`, the overloaded division operator, and `iterdir`. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-39684

    Last Modified: 15 Apr 2026

    Tencent RapidJSON is vulnerable to privilege escalation due to an integer overflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer overflow vulnerability (when the file is parsed), leading to elevation of privilege.

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-40750

    Last Modified: 30 Jun 2025

    Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

    Published: 9 Jul 2024
    8.2
    High

    CVE-2024-37871

    Last Modified: 14 May 2025

    SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Published: 9 Jul 2024
    5.4
    Medium

    CVE-2024-39031

    Last Modified: 5 Jun 2025

    In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.

    Published: 9 Jul 2024
    6.5
    Medium

    CVE-2024-39181

    Last Modified: 20 Aug 2025

    Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 9 Jul 2024
    5.9
    Medium

    CVE-2024-40035

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40737

    Last Modified: 14 Mar 2025

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/add.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2023-48194

    Last Modified: 8 Dec 2025

    Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.

    Published: 9 Jul 2024
    8.2
    High

    CVE-2024-22271

    Last Modified: 15 Apr 2026

    In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when all of the following are true: User is using Spring Cloud Function Web module Affected Spring Products and Versions Spring Cloud Function Framework 4.1.0 to 4.1.2 4.0.0 to 4.0.8 References https://spring.io/security/cve-2022-22979   https://checkmarx.com/blog/spring-function-cloud-dos-cve-2022-22979-and-unintended-function-invocation/  History 2020-01-16: Initial vulnerability report published.

    Published: 9 Jul 2024