CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-37058

    Last Modified: 18 Mar 2025

    Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.

    Published: 17 Jun 2024
    8.4
    High

    CVE-2024-37848

    Last Modified: 5 Nov 2025

    SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-38470

    Last Modified: 30 Apr 2025

    zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

    Published: 17 Jun 2024
    6.3
    Medium

    CVE-2024-38469

    Last Modified: 30 Apr 2025

    zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

    Published: 17 Jun 2024
    8.8
    High

    CVE-2024-37840

    Last Modified: 10 Jun 2025

    SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.

    Published: 17 Jun 2024
    4.8
    Medium

    CVE-2024-37828

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field under the Set Broadcast Message module.

    Published: 17 Jun 2024
    5.9
    Medium

    CVE-2024-37798

    Last Modified: 3 Apr 2025

    Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.

    Published: 17 Jun 2024
    7.5
    High

    CVE-2024-37795

    Last Modified: 15 Apr 2026

    A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` command with specific formatting errors.

    Published: 17 Jun 2024
    9.8
    Critical

    CVE-2024-36543

    Last Modified: 15 Apr 2026

    Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists), and potentially steal Kafka SASL credentials, by querying the MirrorMaker Kafka REST API.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-37622

    Last Modified: 30 Apr 2025

    Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

    Published: 17 Jun 2024
    6.3
    Medium

    CVE-2024-37661

    Last Modified: 6 Jun 2025

    TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

    Published: 17 Jun 2024
    9.8
    Critical

    CVE-2024-36580

    Last Modified: 15 Apr 2026

    A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.

    Published: 17 Jun 2024
    7.6
    High

    CVE-2024-36581

    Last Modified: 15 Apr 2026

    A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

    Published: 17 Jun 2024
    7.4
    High

    CVE-2024-0397

    Last Modified: 15 Apr 2026

    A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

    Published: 17 Jun 2024
    9.8
    Critical

    CVE-2024-34833

    Last Modified: 30 Apr 2025

    Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

    Published: 17 Jun 2024
    6.3
    Medium

    CVE-2024-36574

    Last Modified: 15 Apr 2026

    A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

    Published: 17 Jun 2024
    9.8
    Critical

    CVE-2024-36575

    Last Modified: 15 Apr 2026

    A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

    Published: 17 Jun 2024
    8.3
    High

    CVE-2024-36577

    Last Modified: 15 Apr 2026

    apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.

    Published: 17 Jun 2024
    5.9
    Medium

    CVE-2024-36578

    Last Modified: 15 Apr 2026

    akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

    Published: 17 Jun 2024
    8.1
    High

    CVE-2024-36583

    Last Modified: 15 Apr 2026

    A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.

    Published: 17 Jun 2024
    8.2
    High

    CVE-2024-37305

    Last Modified: 15 Apr 2026

    oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handles lengths decoded with DECODE_UINT32 at the start of serialized hybrid (traditional + post-quantum) keys and signatures. Unchecked length values are later used for memory reads and writes; malformed input can lead to crashes or information leakage. Handling of plain/non-hybrid PQ key operation is not affected. This issue has been patched in in v0.6.1. All users are advised to upgrade. There are no workarounds for this issue.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-37619

    Last Modified: 21 Nov 2024

    StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.

    Published: 17 Jun 2024
    7.2
    High

    CVE-2024-37621

    Last Modified: 20 Jun 2025

    StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-37623

    Last Modified: 30 Apr 2025

    Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-37624

    Last Modified: 17 Mar 2025

    Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

    Published: 17 Jun 2024
    6.1
    Medium

    CVE-2024-37625

    Last Modified: 21 Nov 2024

    zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

    Published: 17 Jun 2024
    6.3
    Medium

    CVE-2024-37662

    Last Modified: 6 Jun 2025

    TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

    Published: 17 Jun 2024
    4.1
    Medium

    CVE-2024-37663

    Last Modified: 9 Jul 2025

    Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

    Published: 17 Jun 2024
    5.2
    Medium

    CVE-2024-37664

    Last Modified: 9 Jul 2025

    Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

    Published: 17 Jun 2024
    7.5
    High

    CVE-2024-37794

    Last Modified: 15 Apr 2026

    Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.

    Published: 17 Jun 2024
    6.9
    Medium

    CVE-2024-6042

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268766 is the identifier assigned to this vulnerability.

    Published: 16 Jun 2024
    5.3
    Medium

    CVE-2024-6041

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268765 was assigned to this vulnerability.

    Published: 16 Jun 2024
    5.3
    Medium

    CVE-2024-6039

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268752.

    Published: 16 Jun 2024
    6.1
    Medium

    CVE-2024-36397

    Last Modified: 21 Nov 2024

    Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 16 Jun 2024
    6.2
    Medium

    CVE-2024-38443

    Last Modified: 15 Apr 2026

    C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

    Published: 16 Jun 2024
    8.8
    High

    CVE-2024-38427

    Last Modified: 15 Apr 2026

    In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.

    Published: 16 Jun 2024
    7.5
    High

    CVE-2024-37890

    Last Modified: 15 Apr 2026

    ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e55e510) and backported to [email protected] (22c2876), [email protected] (eeb76d3), and [email protected] (4abd8f6). In vulnerable versions of ws, the issue can be mitigated in the following ways: 1. Reduce the maximum allowed length of the request headers using the --max-http-header-size=size and/or the maxHeaderSize options so that no more headers than the server.maxHeadersCount limit can be sent. 2. Set server.maxHeadersCount to 0 so that no limit is applied.

    Published: 16 Jun 2024
    9.8
    Critical

    CVE-2024-38468

    Last Modified: 26 Mar 2025

    Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

    Published: 16 Jun 2024
    5.4
    Medium

    CVE-2023-27636

    Last Modified: 21 Nov 2024

    Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

    Published: 16 Jun 2024
    9.8
    Critical

    CVE-2024-38439

    Last Modified: 3 Nov 2025

    Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.

    Published: 16 Jun 2024
    7.5
    High

    CVE-2024-38440

    Last Modified: 3 Nov 2025

    Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vulnerability. This vulnerability arises due to a lack of validation for the length field after parsing user-provided data, leading to an out-of-bounds heap write of one byte (\0). Under specific configurations, this can result in reading metadata of the next heap block, potentially causing a Denial of Service (DoS) under certain heap layouts or with ASAN enabled. ... The vulnerability is located in the FPLoginExt operation of Netatalk, in the BN_bin2bn function found in /etc/uams/uams_dhx_pam.c ... if (!(bn = BN_bin2bn((unsigned char *)ibuf, KEYSIZE, NULL))) ... threads ... [#0] Id 1, Name: "afpd", stopped 0x7ffff4304e58 in ?? (), reason: SIGSEGV ... [#0] 0x7ffff4304e58 mov BYTE PTR [r14+0x8], 0x0 ... mov rdx, QWORD PTR [rsp+0x18] ... afp_login_ext(obj=<optimized out>, ibuf=0x62d000010424 "", ibuflen=0xffffffffffff0015, rbuf=<optimized out>, rbuflen=<optimized out>) ... afp_over_dsi(obj=0x5555556154c0 <obj>).' 2.4.1 and 3.1.19 are also fixed versions.

    Published: 16 Jun 2024
    9.1
    Critical

    CVE-2024-34451

    Last Modified: 20 Jun 2025

    Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

    Published: 16 Jun 2024
    9.8
    Critical

    CVE-2024-38395

    Last Modified: 18 Jun 2025

    In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

    Published: 16 Jun 2024
    9.8
    Critical

    CVE-2024-38396

    Last Modified: 20 Jun 2025

    An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

    Published: 16 Jun 2024
    9.8
    Critical

    CVE-2024-38441

    Last Modified: 3 Nov 2025

    Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.

    Published: 16 Jun 2024
    9.1
    Critical

    CVE-2024-38448

    Last Modified: 15 Apr 2026

    htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

    Published: 16 Jun 2024
    6.1
    Medium

    CVE-2024-38454

    Last Modified: 17 Mar 2025

    ExpressionEngine before 7.4.11 allows XSS.

    Published: 16 Jun 2024
    8.8
    High

    CVE-2024-38457

    Last Modified: 21 Nov 2024

    Xenforo before 2.2.16 allows CSRF.

    Published: 16 Jun 2024
    8.8
    High

    CVE-2024-38458

    Last Modified: 21 Nov 2024

    Xenforo before 2.2.16 allows code injection.

    Published: 16 Jun 2024
    7.8
    High

    CVE-2024-38459

    Last Modified: 16 Jul 2025

    langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.

    Published: 16 Jun 2024