CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-6293

    Last Modified: 13 Feb 2025

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Jun 2024
    8.8
    High

    CVE-2024-6292

    Last Modified: 13 Feb 2025

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Jun 2024
    8.8
    High

    CVE-2024-6291

    Last Modified: 13 Feb 2025

    Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Jun 2024
    8.8
    High

    CVE-2024-6290

    Last Modified: 13 Mar 2025

    Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Jun 2024
    6.9
    Medium

    CVE-2023-45195

    Last Modified: 15 Oct 2025

    Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

    Published: 24 Jun 2024
    6.9
    Medium

    CVE-2023-45196

    Last Modified: 15 Oct 2025

    Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

    Published: 24 Jun 2024
    6.5
    Medium

    CVE-2023-49793

    Last Modified: 21 Nov 2024

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal attack, can load and display files on the machine of `CodeChecker server`. The vulnerable endpoint is `/Default/v6.53/CodeCheckerService@massStoreRun`. The path traversal vulnerability allows reading data on the machine of the `CodeChecker server`, with the same permission level as the `CodeChecker server`. The attack requires a user account on the `CodeChecker server`, with permission to store to a server, and view the stored report. This vulnerability has been patched in version 6.23.

    Published: 24 Jun 2024
    9.9
    Critical

    CVE-2024-38369

    Last Modified: 21 Nov 2024

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right of its author. This means that any user able to modify the target document can impersonate the author of the content which used the `include` macro. This vulnerability has been patched in XWiki 15.0 RC1 by making the default behavior safe.

    Published: 24 Jun 2024
    9.6
    Critical

    CVE-2024-38373

    Last Modified: 21 Nov 2024

    FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name length, could cause the parser to read beyond the DNS response buffer. This issue affects applications using DNS functionality of the FreeRTOS-Plus-TCP stack. Applications that do not use DNS functionality are not affected, even when the DNS functionality is enabled. This vulnerability has been patched in version 4.1.1.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-6287

    Last Modified: 21 Nov 2024

    Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could An attacker to bypass memory range restriction and overwrite an already loaded image partly or completely, which could result in code execution and bypass of secure boot.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-6285

    Last Modified: 21 Nov 2024

    Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading of images to unallowed addresses.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-33687

    Last Modified: 13 Mar 2025

    Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.

    Published: 24 Jun 2024
    8.8
    High

    CVE-2024-4748

    Last Modified: 21 Nov 2024

    The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.  The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server.

    Published: 24 Jun 2024
    3.3
    Low

    CVE-2024-4839

    Last Modified: 7 Jul 2025

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic search Service (under construction), XTTS service, Petals service, vLLM service, and Motion Ctrl service, which lack CSRF protection. This vulnerability allows attackers to deceive users into unwittingly installing the XTTS service among other packages by submitting a malicious installation request. Successful exploitation results in attackers tricking users into performing actions without their consent.

    Published: 24 Jun 2024
    4.3
    Medium

    CVE-2024-37233

    Last Modified: 15 Apr 2026

    Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.

    Published: 24 Jun 2024
    5.3
    Medium

    CVE-2024-3264

    Last Modified: 3 Jun 2026

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14.

    Published: 24 Jun 2024
    8.6
    High

    CVE-2024-37231

    Last Modified: 11 Apr 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon booking system: from n/a through 9.9.

    Published: 24 Jun 2024
    10
    Critical

    CVE-2024-37228

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-37111

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-5862

    Last Modified: 3 Jun 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14.

    Published: 24 Jun 2024
    9.9
    Critical

    CVE-2024-37109

    Last Modified: 21 Nov 2024

    Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.

    Published: 24 Jun 2024
    8.8
    High

    CVE-2024-37107

    Last Modified: 21 Nov 2024

    Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.

    Published: 24 Jun 2024
    8.5
    High

    CVE-2024-37092

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0.

    Published: 24 Jun 2024
    9.9
    Critical

    CVE-2024-37091

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor Widgets: from n/a through 1.2.2.

    Published: 24 Jun 2024
    9
    Critical

    CVE-2024-37089

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0.

    Published: 24 Jun 2024
    6.3
    Medium

    CVE-2024-36038

    Last Modified: 15 Apr 2026

    Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

    Published: 24 Jun 2024
    9.1
    Critical

    CVE-2024-29868

    Last Modified: 15 Jul 2025

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

    Published: 24 Jun 2024
    9.3
    Critical

    CVE-2024-6160

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session cookies or modify the content of pages. This issue affects MegaBIP software versions through 5.12.1.

    Published: 24 Jun 2024
    9.1
    Critical

    CVE-2024-36497

    Last Modified: 15 Apr 2026

    The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

    Published: 24 Jun 2024
    7.5
    High

    CVE-2024-36496

    Last Modified: 15 Apr 2026

    The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application hashes this five-character password with the outdated and broken MD5 algorithm (no salt) and uses the first five bytes as the key for RC4. The configuration file is then encrypted with these parameters.

    Published: 24 Jun 2024
    5.4
    Medium

    CVE-2024-4754

    Last Modified: 3 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS. This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.

    Published: 24 Jun 2024
    9.8
    Critical

    CVE-2024-5683

    Last Modified: 3 Jun 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remote Code Inclusion. This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.

    Published: 24 Jun 2024
    7.7
    High

    CVE-2024-36495

    Last Modified: 15 Apr 2026

    The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

    Published: 24 Jun 2024
    6.1
    Medium

    CVE-2024-27136

    Last Modified: 20 Mar 2025

    XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

    Published: 24 Jun 2024
    6
    Medium

    CVE-2024-24554

    Last Modified: 2 Jan 2026

    Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

    Published: 24 Jun 2024
    5.9
    Medium

    CVE-2024-24553

    Last Modified: 2 Jan 2026

    Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

    Published: 24 Jun 2024
    5.6
    Medium

    CVE-2024-24552

    Last Modified: 2 Jan 2026

    A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into authorizing a session ID of their choosing.

    Published: 24 Jun 2024
    8.9
    High

    CVE-2024-24551

    Last Modified: 2 Jan 2026

    A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

    Published: 24 Jun 2024
    8.9
    High

    CVE-2024-24550

    Last Modified: 2 Jan 2026

    A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

    Published: 24 Jun 2024
    —
    Unknown

    CVE-2024-4460

    Last Modified: 17 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Jun 2024
    6.1
    Medium

    CVE-2024-4900

    Last Modified: 19 May 2025

    The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

    Published: 24 Jun 2024
    5
    Medium

    CVE-2024-4899

    Last Modified: 19 May 2025

    The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

    Published: 24 Jun 2024
    6.3
    Medium

    CVE-2024-4499

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This issue can lead to the reading and writing of audio files and, when combined with other vulnerabilities, could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.

    Published: 24 Jun 2024
    5.3
    Medium

    CVE-2024-6280

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/ajax.php?action=save_settings. The manipulation of the argument img leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269493 was assigned to this vulnerability.

    Published: 24 Jun 2024
    5.3
    Medium

    CVE-2024-6279

    Last Modified: 21 Nov 2024

    A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file examresults-par.php of the component Exam Results Page. The manipulation of the argument sid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269492.

    Published: 24 Jun 2024
    5.1
    Medium

    CVE-2024-6278

    Last Modified: 21 Nov 2024

    A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file subject.php of the component Subject Page. The manipulation of the argument update leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269491.

    Published: 24 Jun 2024
    5.1
    Medium

    CVE-2024-6277

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Affected is an unknown function of the file student.php of the component Student Page. The manipulation of the argument update leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269490 is the identifier assigned to this vulnerability.

    Published: 24 Jun 2024
    5.1
    Medium

    CVE-2024-6276

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. This issue affects some unknown processing of the file teacher.php of the component Teacher Page. The manipulation of the argument update leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269489 was assigned to this vulnerability.

    Published: 24 Jun 2024
    5.1
    Medium

    CVE-2024-6275

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerability affects unknown code of the file parent.php of the component Parent Page. The manipulation of the argument update leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269488.

    Published: 24 Jun 2024
    5.1
    Medium

    CVE-2024-6274

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affects an unknown part of the file /attendancelist.php of the component Attendance Report Page. The manipulation of the argument aid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269487.

    Published: 24 Jun 2024