CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-5573

    Last Modified: 19 May 2025

    The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 26 Jun 2024
    4
    Medium

    CVE-2024-5473

    Last Modified: 19 May 2025

    The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 26 Jun 2024
    5.4
    Medium

    CVE-2024-5199

    Last Modified: 21 Nov 2024

    The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 26 Jun 2024
    4.8
    Medium

    CVE-2024-5169

    Last Modified: 21 Nov 2024

    The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-5071

    Last Modified: 19 May 2025

    The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

    Published: 26 Jun 2024
    4.8
    Medium

    CVE-2024-4959

    Last Modified: 30 Apr 2025

    The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-4957

    Last Modified: 30 Apr 2025

    The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Jun 2024
    7.6
    High

    CVE-2024-4758

    Last Modified: 19 May 2025

    The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

    Published: 26 Jun 2024
    5.4
    Medium

    CVE-2024-3633

    Last Modified: 19 May 2025

    The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 26 Jun 2024
    6.4
    Medium

    CVE-2024-5332

    Last Modified: 8 Apr 2026

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Jun 2024
    5.3
    Medium

    CVE-2024-4106

    Last Modified: 15 Apr 2026

    A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00

    Published: 26 Jun 2024
    5.8
    Medium

    CVE-2024-4105

    Last Modified: 15 Apr 2026

    A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw (Reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product URL containing a malicious request, the malicious script may be executed on the client PC. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00

    Published: 26 Jun 2024
    3.5
    Low

    CVE-2024-37141

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

    Published: 26 Jun 2024
    8.8
    High

    CVE-2024-37140

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system application's underlying OS with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-37139

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to temporary resource constraint of system application. Exploitation may lead to denial of service of the application.

    Published: 26 Jun 2024
    4.1
    Medium

    CVE-2024-37138

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized file to the managed system.

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-27867

    Last Modified: 2 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.

    Published: 26 Jun 2024
    5.9
    Medium

    CVE-2024-29175

    Last Modified: 21 Nov 2024

    Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to man-in-the-middle attack that exposes sensitive session information.

    Published: 26 Jun 2024
    4.4
    Medium

    CVE-2024-29174

    Last Modified: 21 Nov 2024

    Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data.

    Published: 26 Jun 2024
    9.8
    Critical

    CVE-2024-5181

    Last Modified: 15 Jul 2025

    A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this vulnerability by manipulating the path of the vulnerable binary file specified in the backend parameter, allowing the execution of arbitrary code on the system. This issue is due to improper neutralization of special elements used in an OS command, leading to potential full control over the affected system.

    Published: 26 Jun 2024
    6.8
    Medium

    CVE-2024-29173

    Last Modified: 3 Feb 2025

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request Forgery (SSRF) vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to disclosure of information on the application or remote client.

    Published: 26 Jun 2024
    2.7
    Low

    CVE-2024-29177

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the reuse of disclosed information to gain unauthorized access to the application report.

    Published: 26 Jun 2024
    8.8
    High

    CVE-2024-29176

    Last Modified: 21 Nov 2024

    Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

    Published: 26 Jun 2024
    5.9
    Medium

    CVE-2024-28973

    Last Modified: 3 Feb 2025

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scripting Vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a high privileged victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery

    Published: 26 Jun 2024
    6.4
    Medium

    CVE-2024-5173

    Last Modified: 8 Apr 2026

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Jun 2024
    —
    Unknown

    CVE-2024-6341

    Last Modified: 2 Jul 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 26 Jun 2024
    3.5
    Low

    CVE-2024-24764

    Last Modified: 21 Nov 2024

    October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.

    Published: 26 Jun 2024
    9.8
    Critical

    CVE-2024-39243

    Last Modified: 13 Jun 2025

    An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

    Published: 26 Jun 2024
    4
    Medium

    CVE-2024-23765

    Last Modified: 15 Apr 2026

    An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content and length of the frame does not matter. The device needs to be restarted to resume operations.

    Published: 26 Jun 2024
    8.8
    High

    CVE-2024-23767

    Last Modified: 15 Apr 2026

    An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-33326

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.

    Published: 26 Jun 2024
    7.5
    High

    CVE-2024-33329

    Last Modified: 15 Apr 2026

    A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.

    Published: 26 Jun 2024
    5.3
    Medium

    CVE-2024-34580

    Last Modified: 15 Apr 2026

    Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the project disputes this CVE Record on the grounds that any vulnerabilities are the result of a failure to configure XML Security for C++ securely. Even when avoiding this particular issue, any use of this library would need considerable additional code and a deep understanding of the standards and protocols involved to arrive at a secure implementation for any particular use case. We recommend against continued direct use of this library.

    Published: 26 Jun 2024
    7.3
    High

    CVE-2024-34581

    Last Modified: 15 Apr 2026

    The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-35545

    Last Modified: 3 Jul 2025

    MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published: 26 Jun 2024
    7.5
    High

    CVE-2024-36829

    Last Modified: 20 Oct 2025

    Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-37571

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter.

    Published: 26 Jun 2024
    9.8
    Critical

    CVE-2024-37734

    Last Modified: 1 May 2025

    An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-38949

    Last Modified: 6 Jun 2025

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

    Published: 26 Jun 2024
    6.5
    Medium

    CVE-2024-38950

    Last Modified: 6 Jun 2025

    Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-39241

    Last Modified: 18 Mar 2025

    Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-39242

    Last Modified: 26 Mar 2025

    A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-39459

    Last Modified: 10 Oct 2025

    In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).

    Published: 26 Jun 2024
    3.1
    Low

    CVE-2024-39458

    Last Modified: 10 Oct 2025

    When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.

    Published: 26 Jun 2024
    4.3
    Medium

    CVE-2024-39460

    Last Modified: 10 Oct 2025

    Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

    Published: 26 Jun 2024
    6.3
    Medium

    CVE-2023-26877

    Last Modified: 15 Apr 2026

    File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.

    Published: 26 Jun 2024
    2.1
    Low

    CVE-2024-21520

    Last Modified: 15 Apr 2026

    Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.

    Published: 26 Jun 2024
    7.5
    High

    CVE-2024-23766

    Last Modified: 15 Apr 2026

    An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-33327

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.

    Published: 26 Jun 2024
    6.1
    Medium

    CVE-2024-33328

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.

    Published: 26 Jun 2024