CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-5460

    Last Modified: 4 Feb 2025

    A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device.

    Published: 25 Jun 2024
    7.2
    High

    CVE-2024-38526

    Last Modified: 15 Apr 2026

    pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.

    Published: 25 Jun 2024
    2.6
    Low

    CVE-2024-38364

    Last Modified: 15 Apr 2026

    DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user's browser may execute any embedded JavaScript. If that embedded JavaScript is malicious, there is a risk of an XSS attack. This vulnerability has been patched in version 7.6.2.

    Published: 25 Jun 2024
    5.9
    Medium

    CVE-2024-29954

    Last Modified: 21 Nov 2024

    A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is incorrectly entered or points to an erroneous file, the firmware download log captures the failed command, including any password entered in the command line.

    Published: 25 Jun 2024
    7.2
    High

    CVE-2024-4869

    Last Modified: 8 Apr 2026

    The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Jun 2024
    4.3
    Medium

    CVE-2024-29953

    Last Modified: 4 Feb 2025

    A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.

    Published: 25 Jun 2024
    9.3
    Critical

    CVE-2024-6060

    Last Modified: 15 Apr 2026

    An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

    Published: 25 Jun 2024
    5.4
    Medium

    CVE-2024-30112

    Last Modified: 28 Oct 2025

    HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.

    Published: 25 Jun 2024
    5.3
    Medium

    CVE-2024-5019

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

    Published: 25 Jun 2024
    5.3
    Medium

    CVE-2024-5018

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .

    Published: 25 Jun 2024
    6.5
    Medium

    CVE-2024-5017

    Last Modified: 13 Feb 2025

    In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure.

    Published: 25 Jun 2024
    7.2
    High

    CVE-2024-5016

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage for clients.

    Published: 25 Jun 2024
    7.1
    High

    CVE-2024-5015

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin.

    Published: 25 Jun 2024
    7.1
    High

    CVE-2024-5014

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.

    Published: 25 Jun 2024
    7.5
    High

    CVE-2024-5013

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

    Published: 25 Jun 2024
    8.6
    High

    CVE-2024-5012

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.

    Published: 25 Jun 2024
    8.8
    High

    CVE-2024-38516

    Last Modified: 15 Apr 2026

    ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.

    Published: 25 Jun 2024
    7.5
    High

    CVE-2024-6206

    Last Modified: 15 Apr 2026

    A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying container leading to complete takeover of the target system.

    Published: 25 Jun 2024
    7.5
    High

    CVE-2024-5011

    Last Modified: 13 Feb 2025

    In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.

    Published: 25 Jun 2024
    7.5
    High

    CVE-2024-5010

    Last Modified: 13 Feb 2025

    In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information.

    Published: 25 Jun 2024
    8.4
    High

    CVE-2024-5009

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

    Published: 25 Jun 2024
    8.8
    High

    CVE-2024-5008

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

    Published: 25 Jun 2024
    7.7
    High

    CVE-2024-4498

    Last Modified: 9 Jul 2025

    A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db_name` parameter to traverse the file system and include arbitrary files. This issue is compounded by the bypass of input filtering in the `install_binding`, `reinstall_binding`, and `unInstall_binding` endpoints, despite the presence of a `sanitize_path_from_endpoint(data.name)` filter. Successful exploitation enables an attacker to upload and execute malicious code on the victim's system, leading to Remote Code Execution (RCE).

    Published: 25 Jun 2024
    9.8
    Critical

    CVE-2024-4885

    Last Modified: 31 Oct 2025

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

    Published: 25 Jun 2024
    9.8
    Critical

    CVE-2024-4884

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

    Published: 25 Jun 2024
    9.8
    Critical

    CVE-2024-4883

    Last Modified: 21 Nov 2024

    In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

    Published: 25 Jun 2024
    4.3
    Medium

    CVE-2024-37167

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.

    Published: 25 Jun 2024
    9.8
    Critical

    CVE-2024-5276

    Last Modified: 4 Apr 2025

    A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.

    Published: 25 Jun 2024
    6.9
    Medium

    CVE-2024-6308

    Last Modified: 18 Feb 2026

    A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269620.

    Published: 25 Jun 2024
    7.4
    High

    CVE-2024-6238

    Last Modified: 23 Sept 2025

    pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.

    Published: 25 Jun 2024
    8.7
    High

    CVE-2024-5990

    Last Modified: 27 Aug 2025

    Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.

    Published: 25 Jun 2024
    9.3
    Critical

    CVE-2024-5989

    Last Modified: 27 Aug 2025

    Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

    Published: 25 Jun 2024
    9.3
    Critical

    CVE-2024-5988

    Last Modified: 27 Aug 2025

    Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

    Published: 25 Jun 2024
    3.5
    Low

    CVE-2023-37541

    Last Modified: 29 Oct 2025

    HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

    Published: 25 Jun 2024
    9.1
    Critical

    CVE-2024-5806

    Last Modified: 16 Jan 2025

    Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

    Published: 25 Jun 2024
    9.1
    Critical

    CVE-2024-5805

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.

    Published: 25 Jun 2024
    5.3
    Medium

    CVE-2024-37087

    Last Modified: 27 Jun 2025

    The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

    Published: 25 Jun 2024
    6.8
    Medium

    CVE-2024-37086

    Last Modified: 27 Jun 2025

    VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.

    Published: 25 Jun 2024
    6.8
    Medium

    CVE-2024-37085

    Last Modified: 30 Oct 2025

    VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

    Published: 25 Jun 2024
    7.2
    High

    CVE-2024-21827

    Last Modified: 4 Nov 2025

    A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 25 Jun 2024
    6.4
    Medium

    CVE-2024-5451

    Last Modified: 15 Apr 2026

    The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Icon and Heading widgets in all versions up to, and including, 11.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Jun 2024
    5
    Medium

    CVE-2024-32111

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9, from 5.8 through 5.8.9, from 5.7 through 5.7.11, from 5.6 through 5.6.13, from 5.5 through 5.5.14, from 5.4 through 5.4.15, from 5.3 through 5.3.17, from 5.2 through 5.2.20, from 5.1 through 5.1.18, from 5.0 through 5.0.21, from 4.9 through 4.9.25, from 4.8 through 4.8.24, from 4.7 through 4.7.28, from 4.6 through 4.6.28, from 4.5 through 4.5.31, from 4.4 through 4.4.32, from 4.3 through 4.3.33, from 4.2 through 4.2.37, from 4.1 through 4.1.40.

    Published: 25 Jun 2024
    4.8
    Medium

    CVE-2024-6299

    Last Modified: 21 Nov 2024

    Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

    Published: 25 Jun 2024
    5.3
    Medium

    CVE-2024-6301

    Last Modified: 21 Nov 2024

    Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

    Published: 25 Jun 2024
    8.1
    High

    CVE-2024-6302

    Last Modified: 21 Nov 2024

    Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.

    Published: 25 Jun 2024
    9.9
    Critical

    CVE-2024-6303

    Last Modified: 21 Nov 2024

    Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the server's key, deactivating users, and more

    Published: 25 Jun 2024
    3.7
    Low

    CVE-2024-6300

    Last Modified: 21 Nov 2024

    Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction

    Published: 25 Jun 2024
    6.5
    Medium

    CVE-2024-31111

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.

    Published: 25 Jun 2024
    10
    Critical

    CVE-2024-5261

    Last Modified: 23 Dec 2025

    Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers. In affected versions of LibreOffice, when used in LibreOfficeKit mode only, then curl's TLS certification verification was disabled (CURLOPT_SSL_VERIFYPEER of false) In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true. This issue affects LibreOffice before version 24.2.4.

    Published: 25 Jun 2024
    6.3
    Medium

    CVE-2024-4846

    Last Modified: 28 Mar 2025

    Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

    Published: 25 Jun 2024