CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-20890

    Last Modified: 21 Nov 2024

    Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

    Published: 2 Jul 2024
    5.9
    Medium

    CVE-2024-20889

    Last Modified: 21 Nov 2024

    Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

    Published: 2 Jul 2024
    7.8
    High

    CVE-2024-20888

    Last Modified: 21 Nov 2024

    Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

    Published: 2 Jul 2024
    7.5
    High

    CVE-2024-4836

    Last Modified: 15 Apr 2026

    Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user. The issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January 2014. Higher versions were never affected.

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-5260

    Last Modified: 8 Apr 2026

    The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘read_more_text’ parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    8.2
    High

    CVE-2024-37077

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

    Published: 2 Jul 2024
    8.2
    High

    CVE-2024-37185

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

    Published: 2 Jul 2024
    8.2
    High

    CVE-2024-36260

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

    Published: 2 Jul 2024
    3.3
    Low

    CVE-2024-36278

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

    Published: 2 Jul 2024
    8.2
    High

    CVE-2024-36243

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

    Published: 2 Jul 2024
    8.2
    High

    CVE-2024-37030

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

    Published: 2 Jul 2024
    3.3
    Low

    CVE-2024-31071

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

    Published: 2 Jul 2024
    4.3
    Medium

    CVE-2024-38857

    Last Modified: 4 Dec 2024

    Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.

    Published: 2 Jul 2024
    5.3
    Medium

    CVE-2023-41928

    Last Modified: 15 Apr 2026

    The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.

    Published: 2 Jul 2024
    5.3
    Medium

    CVE-2023-41927

    Last Modified: 15 Apr 2026

    The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of cryptographic weaknesses.

    Published: 2 Jul 2024
    8.8
    High

    CVE-2023-41926

    Last Modified: 15 Apr 2026

    The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.

    Published: 2 Jul 2024
    7.2
    High

    CVE-2023-41923

    Last Modified: 15 Apr 2026

    The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

    Published: 2 Jul 2024
    7.2
    High

    CVE-2023-41922

    Last Modified: 21 Nov 2024

    A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in multiple instances of Stored XSS vulnerabilities.

    Published: 2 Jul 2024
    9.8
    Critical

    CVE-2023-41921

    Last Modified: 15 Apr 2026

    A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving the modification of the target’s integrity to achieve an insecure state.

    Published: 2 Jul 2024
    9.8
    Critical

    CVE-2023-41920

    Last Modified: 15 Apr 2026

    The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.

    Published: 2 Jul 2024
    9.8
    Critical

    CVE-2023-41919

    Last Modified: 21 Nov 2024

    Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

    Published: 2 Jul 2024
    10
    Critical

    CVE-2023-41918

    Last Modified: 15 Apr 2026

    A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functions, or even the execution of arbitrary code.

    Published: 2 Jul 2024
    10
    Critical

    CVE-2023-41917

    Last Modified: 15 Apr 2026

    Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized code execution.

    Published: 2 Jul 2024
    8.5
    High

    CVE-2024-37479

    Last Modified: 10 Jul 2025

    Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1.

    Published: 2 Jul 2024
    6.1
    Medium

    CVE-2024-5544

    Last Modified: 8 Apr 2026

    The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 2 Jul 2024
    5.3
    Medium

    CVE-2024-5545

    Last Modified: 8 Apr 2026

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-3513

    Last Modified: 8 Apr 2026

    The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-6362 appears to be a duplicate of this issue.

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-5504

    Last Modified: 8 Apr 2026

    The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    6.7
    Medium

    CVE-2024-37126

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.

    Published: 2 Jul 2024
    6.7
    Medium

    CVE-2024-37134

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access.

    Published: 2 Jul 2024
    6.7
    Medium

    CVE-2024-37133

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access.

    Published: 2 Jul 2024
    6.7
    Medium

    CVE-2024-37132

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges.

    Published: 2 Jul 2024
    6.7
    Medium

    CVE-2024-32854

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation.

    Published: 2 Jul 2024
    4.4
    Medium

    CVE-2024-32853

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 2 Jul 2024
    5.9
    Medium

    CVE-2024-32852

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks.

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-5219

    Last Modified: 8 Apr 2026

    The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    9.8
    Critical

    CVE-2024-6172

    Last Modified: 8 Apr 2026

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2024-37252 appears to be a duplicate of this issue.

    Published: 2 Jul 2024
    8.8
    High

    CVE-2024-5767

    Last Modified: 21 Nov 2024

    The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 2 Jul 2024
    8.8
    High

    CVE-2024-5606

    Last Modified: 21 Nov 2024

    The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

    Published: 2 Jul 2024
    5.4
    Medium

    CVE-2024-4627

    Last Modified: 21 Nov 2024

    The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 2 Jul 2024
    4.8
    Medium

    CVE-2024-3999

    Last Modified: 21 Nov 2024

    The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-1427

    Last Modified: 8 Apr 2026

    The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    8.8
    High

    CVE-2024-5349

    Last Modified: 8 Apr 2026

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-5419

    Last Modified: 8 Apr 2026

    The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    5.1
    Medium

    CVE-2024-0158

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges

    Published: 2 Jul 2024
    6.4
    Medium

    CVE-2024-5938

    Last Modified: 8 Apr 2026

    The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Jul 2024
    5.1
    Medium

    CVE-2024-2819

    Last Modified: 21 Jan 2025

    Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.

    Published: 2 Jul 2024
    7.8
    High

    CVE-2024-4679

    Last Modified: 15 Apr 2026

    Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows allows File Manipulation.This issue affects JP1/Extensible SNMP Agent for Windows: from 12-00 before 12-00-01, from 11-00 through 11-00-*; JP1/Extensible SNMP Agent: from 10-10 through 10-10-01, from 10-00 through 10-00-02, from 09-00 through 09-00-04; Job Management Partner1/Extensible SNMP Agent: from 10-10 through 10-10-01, from 10-00 through 10-00-02, from 09-00 through 09-00-04.

    Published: 2 Jul 2024
    5.4
    Medium

    CVE-2024-39143

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.

    Published: 2 Jul 2024
    7.8
    High

    CVE-2022-25478

    Last Modified: 21 Nov 2024

    Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.

    Published: 2 Jul 2024