CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2024-28832

    Last Modified: 4 Dec 2024

    Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

    Published: 25 Jun 2024
    5.4
    Medium

    CVE-2024-28831

    Last Modified: 4 Dec 2024

    Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.

    Published: 25 Jun 2024
    5.3
    Medium

    CVE-2024-0171

    Last Modified: 21 Nov 2024

    Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.

    Published: 25 Jun 2024
    6.4
    Medium

    CVE-2024-6307

    Last Modified: 15 Apr 2026

    WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Jun 2024
    —
    Unknown

    CVE-2024-6306

    Last Modified: 25 Jun 2024

    **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-32111.

    Published: 25 Jun 2024
    —
    Unknown

    CVE-2024-6305

    Last Modified: 25 Jun 2024

    **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-31111.

    Published: 25 Jun 2024
    —
    Unknown

    CVE-2024-6304

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 Jun 2024
    7.5
    High

    CVE-2024-5216

    Last Modified: 15 Jul 2025

    A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to create users with excessively bulky texts in the username field. This exploit results in the user management panel becoming unresponsive, preventing administrators from performing critical user management actions such as editing, suspending, or deleting users. The impact of this vulnerability includes administrative paralysis, compromised security, and operational disruption, as it allows malicious users to perpetuate their presence within the system indefinitely, undermines the system's security posture, and degrades overall system performance.

    Published: 25 Jun 2024
    6.3
    Medium

    CVE-2024-4641

    Last Modified: 21 Nov 2024

    OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.

    Published: 25 Jun 2024
    7.1
    High

    CVE-2024-4640

    Last Modified: 21 Nov 2024

    OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash.

    Published: 25 Jun 2024
    7.1
    High

    CVE-2024-4639

    Last Modified: 21 Nov 2024

    OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.

    Published: 25 Jun 2024
    5.4
    Medium

    CVE-2024-34142

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 25 Jun 2024
    5.4
    Medium

    CVE-2024-34141

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 25 Jun 2024
    7.1
    High

    CVE-2024-4638

    Last Modified: 21 Nov 2024

    OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.

    Published: 25 Jun 2024
    9.8
    Critical

    CVE-2024-6028

    Last Modified: 8 Apr 2026

    The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 25 Jun 2024
    4.3
    Medium

    CVE-2024-3249

    Last Modified: 15 Apr 2026

    The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_xml_data, xml_data_import, import_option_data, import_widgets, and import_customizer_settings functions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create pages, update certain options, including WooCommerce page titles and Elementor settings, import widgets, and update the plugin's customizer settings and the WordPress custom CSS. NOTE: This vulnerability was partially fixed in version 1.6.2.

    Published: 25 Jun 2024
    5.5
    Medium

    CVE-2024-4759

    Last Modified: 19 May 2025

    The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 25 Jun 2024
    8.1
    High

    CVE-2024-4757

    Last Modified: 19 May 2025

    The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 25 Jun 2024
    8.8
    High

    CVE-2024-5431

    Last Modified: 8 Apr 2026

    The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, potentially resulting in code execution

    Published: 25 Jun 2024
    3.8
    Low

    CVE-2024-32855

    Last Modified: 4 Feb 2025

    Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

    Published: 25 Jun 2024
    9.9
    Critical

    CVE-2024-4197

    Last Modified: 21 Jan 2025

    An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.

    Published: 25 Jun 2024
    10
    Critical

    CVE-2024-4196

    Last Modified: 1 Oct 2025

    An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37007

    Last Modified: 27 Aug 2025

    A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-36999

    Last Modified: 13 Nov 2025

    A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23159

    Last Modified: 13 Nov 2025

    A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23158

    Last Modified: 13 Nov 2025

    A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23157

    Last Modified: 22 Jan 2026

    A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

    Published: 25 Jun 2024
    10
    Critical

    CVE-2024-6297

    Last Modified: 15 Apr 2026

    Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23156

    Last Modified: 22 Jan 2026

    A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23155

    Last Modified: 26 Aug 2025

    A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23154

    Last Modified: 13 Nov 2025

    A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23153

    Last Modified: 13 Nov 2025

    A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23152

    Last Modified: 13 Nov 2025

    A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23151

    Last Modified: 26 Aug 2025

    A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23150

    Last Modified: 13 Nov 2025

    A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37006

    Last Modified: 22 Jan 2026

    A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37005

    Last Modified: 13 Nov 2025

    A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37004

    Last Modified: 13 Nov 2025

    A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37003

    Last Modified: 13 Nov 2025

    A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37002

    Last Modified: 13 Nov 2025

    A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37001

    Last Modified: 13 Nov 2025

    A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-37000

    Last Modified: 22 Jan 2026

    A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23149

    Last Modified: 13 Nov 2025

    A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23148

    Last Modified: 22 Jan 2026

    A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23147

    Last Modified: 22 Jan 2026

    A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23146

    Last Modified: 13 Nov 2025

    A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23145

    Last Modified: 13 Nov 2025

    A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024
    8.7
    High

    CVE-2023-5038

    Last Modified: 21 Nov 2024

    badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

    Published: 25 Jun 2024
    3.9
    Low

    CVE-2024-6295

    Last Modified: 15 Apr 2026

    udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.

    Published: 25 Jun 2024
    7.8
    High

    CVE-2024-23144

    Last Modified: 14 Nov 2025

    A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 25 Jun 2024