CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-35155

    Last Modified: 21 Nov 2024

    IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292765.

    Published: 28 Jun 2024
    7.5
    High

    CVE-2024-31912

    Last Modified: 21 Nov 2024

    IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM X-Force ID: 289894.

    Published: 28 Jun 2024
    5.9
    Medium

    CVE-2024-31919

    Last Modified: 21 Nov 2024

    IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.

    Published: 28 Jun 2024
    8.8
    High

    CVE-2024-37905

    Last Modified: 21 Aug 2025

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including resetting user passwords and more. This issue has been patched in version(s) 2024.2.4, 2024.4.2 and 2024.6.0.

    Published: 28 Jun 2024
    6.3
    Medium

    CVE-2024-38522

    Last Modified: 21 Nov 2024

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.

    Published: 28 Jun 2024
    7.1
    High

    CVE-2024-6403

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269948. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jun 2024
    7.1
    High

    CVE-2024-6402

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269947. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jun 2024
    6.2
    Medium

    CVE-2024-35139

    Last Modified: 3 Nov 2025

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.

    Published: 28 Jun 2024
    8.8
    High

    CVE-2024-38521

    Last Modified: 21 Nov 2024

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored XSS in the Inbox. The input is displayed using the `safe` Jinja2 attribute, and thus not sanitized upon display. This issue has been patched in version 0.1.0.

    Published: 28 Jun 2024
    6.2
    Medium

    CVE-2024-35137

    Last Modified: 3 Nov 2025

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

    Published: 28 Jun 2024
    3.6
    Low

    CVE-2024-38531

    Last Modified: 15 Apr 2026

    Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.

    Published: 28 Jun 2024
    9.8
    Critical

    CVE-2024-3816

    Last Modified: 21 Nov 2024

    Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar.  Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

    Published: 28 Jun 2024
    6.1
    Medium

    CVE-2024-3801

    Last Modified: 21 Nov 2024

    Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters.  Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

    Published: 28 Jun 2024
    6.1
    Medium

    CVE-2024-3800

    Last Modified: 13 Mar 2025

    Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested file names.  Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.

    Published: 28 Jun 2024
    6.3
    Medium

    CVE-2024-5737

    Last Modified: 21 Nov 2024

    Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0.

    Published: 28 Jun 2024
    8.2
    High

    CVE-2024-5736

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0.

    Published: 28 Jun 2024
    6.3
    Medium

    CVE-2024-5735

    Last Modified: 21 Nov 2024

    Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5922

    Last Modified: 15 Apr 2026

    The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5662

    Last Modified: 15 Apr 2026

    The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the Social Count (Static) widget in all versions up to, and including, 3.11.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5925

    Last Modified: 15 Apr 2026

    The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5424

    Last Modified: 15 Apr 2026

    The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘galleryID’ and 'className' parameters in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    3.3
    Low

    CVE-2024-30135

    Last Modified: 30 Oct 2025

    HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

    Published: 28 Jun 2024
    4.7
    Medium

    CVE-2024-6288

    Last Modified: 15 Apr 2026

    The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 28 Jun 2024
    5.3
    Medium

    CVE-2024-2795

    Last Modified: 15 Apr 2026

    The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.1 via META description. This makes it possible for unauthenticated attackers to extract limited information about password protected posts.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5796

    Last Modified: 15 Apr 2026

    The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-5788

    Last Modified: 15 Apr 2026

    The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's Button shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    7.5
    High

    CVE-2024-39350

    Last Modified: 21 Nov 2024

    A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    3.3
    Low

    CVE-2024-30111

    Last Modified: 30 Oct 2025

    HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device due to which malicious users can gain unauthorized access to the rooted devices, compromising security and potentially leading to data breaches or other malicious activities.

    Published: 28 Jun 2024
    7.5
    High

    CVE-2024-39348

    Last Modified: 7 Aug 2025

    Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.

    Published: 28 Jun 2024
    5.9
    Medium

    CVE-2024-39347

    Last Modified: 7 Aug 2025

    Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.

    Published: 28 Jun 2024
    3.7
    Low

    CVE-2024-30110

    Last Modified: 30 Oct 2025

    HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.

    Published: 28 Jun 2024
    4.9
    Medium

    CVE-2024-39352

    Last Modified: 10 Apr 2025

    A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote authenticated users with administrator privileges to bypass firmware integrity check via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    7.2
    High

    CVE-2024-39351

    Last Modified: 10 Apr 2025

    A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    9.8
    Critical

    CVE-2024-39349

    Last Modified: 10 Apr 2025

    A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the upstream library. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    5.3
    Medium

    CVE-2023-47803

    Last Modified: 10 Apr 2025

    A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings functionality. This allows remote attackers to read specific files containing non-sensitive information via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    7.2
    High

    CVE-2023-47802

    Last Modified: 10 Apr 2025

    A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows remote authenticated users with administrator privileges to execute arbitrary commands via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.

    Published: 28 Jun 2024
    6.1
    Medium

    CVE-2024-5730

    Last Modified: 19 May 2025

    The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 28 Jun 2024
    6.1
    Medium

    CVE-2024-5729

    Last Modified: 19 May 2025

    The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 28 Jun 2024
    5.4
    Medium

    CVE-2024-5728

    Last Modified: 19 May 2025

    The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 28 Jun 2024
    4.7
    Medium

    CVE-2024-5727

    Last Modified: 19 May 2025

    The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 28 Jun 2024
    6.5
    Medium

    CVE-2024-5570

    Last Modified: 27 Aug 2025

    The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

    Published: 28 Jun 2024
    3.7
    Low

    CVE-2024-30109

    Last Modified: 30 Oct 2025

    HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.

    Published: 28 Jun 2024
    8.1
    High

    CVE-2024-37282

    Last Modified: 30 Jan 2026

    It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.

    Published: 28 Jun 2024
    6.4
    Medium

    CVE-2024-6296

    Last Modified: 15 Apr 2026

    The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ parameter in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jun 2024
    4.3
    Medium

    CVE-2024-5864

    Last Modified: 15 Apr 2026

    The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the plugin's settings.

    Published: 28 Jun 2024
    5.4
    Medium

    CVE-2024-5863

    Last Modified: 15 Apr 2026

    The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in all versions up to, and including, 1.13.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to erase all of the content in arbitrary posts.

    Published: 28 Jun 2024
    3.8
    Low

    CVE-2024-37137

    Last Modified: 3 Feb 2025

    Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.

    Published: 28 Jun 2024
    6.1
    Medium

    CVE-2024-39828

    Last Modified: 15 Apr 2026

    R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.

    Published: 28 Jun 2024
    9.1
    Critical

    CVE-2019-25211

    Last Modified: 15 Apr 2026

    parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.

    Published: 28 Jun 2024
    8.1
    High

    CVE-2024-27628

    Last Modified: 11 Jun 2025

    Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

    Published: 28 Jun 2024