CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2024-36755

    Last Modified: 9 Jul 2025

    D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.

    Published: 27 Jun 2024
    3.8
    Low

    CVE-2024-39157

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.

    Published: 27 Jun 2024
    9.4
    Critical

    CVE-2024-36059

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

    Published: 27 Jun 2024
    9.8
    Critical

    CVE-2024-36072

    Last Modified: 15 Apr 2026

    Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector and Unify server application which allows an unauthenticated remote attacker to send a malicious request, resulting in the ability to execute system commands with root privileges.

    Published: 27 Jun 2024
    6.5
    Medium

    CVE-2024-36075

    Last Modified: 15 Apr 2026

    The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpoint. An attacker who is able to modify the archive on the server could obtain remote code execution as an administrator on an endpoint.

    Published: 27 Jun 2024
    4.3
    Medium

    CVE-2024-39133

    Last Modified: 7 Jul 2025

    Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.

    Published: 27 Jun 2024
    7.5
    High

    CVE-2024-39134

    Last Modified: 10 Jul 2025

    A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.

    Published: 27 Jun 2024
    4.7
    Medium

    CVE-2024-39153

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.

    Published: 27 Jun 2024
    8.8
    High

    CVE-2024-39154

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.

    Published: 27 Jun 2024
    6.8
    Medium

    CVE-2024-39155

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.

    Published: 27 Jun 2024
    3.8
    Low

    CVE-2024-39156

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.

    Published: 27 Jun 2024
    8.8
    High

    CVE-2024-39158

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.

    Published: 27 Jun 2024
    8.2
    High

    CVE-2024-39207

    Last Modified: 15 Apr 2026

    lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.

    Published: 27 Jun 2024
    9.8
    Critical

    CVE-2024-39208

    Last Modified: 15 Apr 2026

    luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.

    Published: 27 Jun 2024
    6.3
    Medium

    CVE-2024-39209

    Last Modified: 15 Apr 2026

    luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

    Published: 27 Jun 2024
    9.8
    Critical

    CVE-2024-39669

    Last Modified: 15 Apr 2026

    In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

    Published: 27 Jun 2024
    6.5
    Medium

    CVE-2024-5642

    Last Modified: 21 Apr 2026

    CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured).

    Published: 27 Jun 2024
    5.3
    Medium

    CVE-2024-2191

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-3115

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-3959

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

    Published: 26 Jun 2024
    3.1
    Low

    CVE-2024-4011

    Last Modified: 9 Jan 2025

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-4557

    Last Modified: 21 Nov 2024

    Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

    Published: 26 Jun 2024
    8.7
    High

    CVE-2024-4901

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, where a stored XSS vulnerability could be imported from a project with malicious commit notes.

    Published: 26 Jun 2024
    9.6
    Critical

    CVE-2024-5655

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

    Published: 26 Jun 2024
    6.8
    Medium

    CVE-2024-5430

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

    Published: 26 Jun 2024
    7.5
    High

    CVE-2024-6323

    Last Modified: 21 Nov 2024

    Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.

    Published: 26 Jun 2024
    8.8
    High

    CVE-2024-28984

    Last Modified: 21 Nov 2024

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

    Published: 26 Jun 2024
    8.8
    High

    CVE-2024-28983

    Last Modified: 10 Apr 2025

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

    Published: 26 Jun 2024
    7.1
    High

    CVE-2024-28982

    Last Modified: 21 Nov 2024

    Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-37247

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in twinpictures, baden03 jQuery T(-) Countdown Widget allows Stored XSS.This issue affects jQuery T(-) Countdown Widget: from n/a through 2.3.25.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-37248

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Anima allows Stored XSS.This issue affects Anima: from n/a through 1.4.1.

    Published: 26 Jun 2024
    6.9
    Medium

    CVE-2024-6355

    Last Modified: 15 Apr 2026

    A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269755. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jun 2024
    10
    Critical

    CVE-2024-1839

    Last Modified: 26 Sept 2025

    Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.

    Published: 26 Jun 2024
    5.4
    Medium

    CVE-2024-38527

    Last Modified: 15 Apr 2026

    ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a renderer to create and modify sequence diagrams. Markdown-based comments in the ZenUML diagram syntax are susceptible to Cross-site Scripting (XSS). The comment feature allows the user to attach small notes for reference. This feature allows the user to enter in their comment in markdown comment, allowing them to use common markdown features, such as `**` for bolded text. However, the markdown text is currently not sanitized before rendering, allowing an attacker to enter a malicious payload for the comment which leads to XSS. This puts existing applications that use ZenUML unsandboxed at risk of arbitrary JavaScript execution when rendering user-controlled diagrams. This vulnerability was patched in version 3.23.25,

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-1493

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

    Published: 26 Jun 2024
    5.3
    Medium

    CVE-2024-1816

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

    Published: 26 Jun 2024
    5.3
    Medium

    CVE-2024-38520

    Last Modified: 15 Apr 2026

    SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enabled on a device, it introduces the possibility of the host being used for amplification/reflection traffic generation because it will respond to every packet with two response packets that are larger than the request packet size. These sorts of techniques are used by external actors who generate spoofed source IPs to target a destination on the internet. This vulnerability has been patched in version 5.02.5185.

    Published: 26 Jun 2024
    5.3
    Medium

    CVE-2024-38375

    Last Modified: 15 Apr 2026

    @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a guest trap causing services to return a 500. This bug has been fixed in version 3.16.0 of the `@fastly/js-compute` package.

    Published: 26 Jun 2024
    7.2
    High

    CVE-2024-6354

    Last Modified: 28 Mar 2025

    Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

    Published: 26 Jun 2024
    3.1
    Low

    CVE-2024-25637

    Last Modified: 29 Sept 2025

    October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.

    Published: 26 Jun 2024
    7.1
    High

    CVE-2024-38272

    Last Modified: 21 Nov 2024

    There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above

    Published: 26 Jun 2024
    5.9
    Medium

    CVE-2024-38271

    Last Modified: 21 Nov 2024

    There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the attacker forces the victim to connect to the attacker’s WiFi network and then sends an OfflineFrame that crashes Quick Share. This makes the Wifi connection to the attacker’s network last, instead of returning to the old network when the Quick Share session completes, allowing the attacker to be a MiTM. We recommend upgrading to version 1.0.1724.0 of Quick Share or above

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-4604

    Last Modified: 3 Jun 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1.

    Published: 26 Jun 2024
    9.8
    Critical

    CVE-2024-4228

    Last Modified: 3 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability in Magarsus Consultancy SSO (Single Sign On) allows SQL Injection. This issue affects SSO (Single Sign On): from 1.0 before 1.1.

    Published: 26 Jun 2024
    —
    Unknown

    CVE-2024-6349

    Last Modified: 26 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 26 Jun 2024
    4.4
    Medium

    CVE-2024-37098

    Last Modified: 7 Jan 2026

    Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.

    Published: 26 Jun 2024
    1.9
    Low

    CVE-2024-6344

    Last Modified: 10 Jul 2025

    A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. The vendor explains, that "[s]ince ZKBio CVSecurity v5000 has been withdrawn from the market, we recommend upgrading to ZKBio CVSecurity V6600 6.1.3_R or above". This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 26 Jun 2024
    9.3
    Critical

    CVE-2024-37252

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.

    Published: 26 Jun 2024
    2.7
    Low

    CVE-2024-28830

    Last Modified: 4 Dec 2024

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.

    Published: 26 Jun 2024
    6.4
    Medium

    CVE-2024-5215

    Last Modified: 8 Apr 2026

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Jun 2024