CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-37882

    Last Modified: 21 Nov 2024

    Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.

    Published: 14 Jun 2024
    —
    Unknown

    CVE-2024-6002

    Last Modified: 16 Dec 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jun 2024
    4.6
    Medium

    CVE-2024-37317

    Last Modified: 21 Nov 2024

    The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3.

    Published: 14 Jun 2024
    4.6
    Medium

    CVE-2024-37316

    Last Modified: 21 Nov 2024

    Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.

    Published: 14 Jun 2024
    3.5
    Low

    CVE-2024-37315

    Last Modified: 21 Nov 2024

    Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3.

    Published: 14 Jun 2024
    3.5
    Low

    CVE-2024-37314

    Last Modified: 21 Nov 2024

    Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.

    Published: 14 Jun 2024
    7.3
    High

    CVE-2024-37313

    Last Modified: 26 Sept 2025

    Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and Nextcloud Enterprise Server is upgraded to 21.0.9.17, 22.2.10.22, 23.0.12.17, 24.0.12.13, 25.0.13.8, 26.0.13, 27.1.8 or 28.0.4.

    Published: 14 Jun 2024
    6.3
    Medium

    CVE-2024-37312

    Last Modified: 14 Aug 2025

    user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user backend is upgraded to 3.0.0 (Nextcloud 20-23), 4.0.0 (Nexcloud 24) or 5.0.0 (Nextcloud 25-28).

    Published: 14 Jun 2024
    8.1
    High

    CVE-2024-34694

    Last Modified: 15 Apr 2026

    LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.

    Published: 14 Jun 2024
    8.2
    High

    CVE-2024-37368

    Last Modified: 31 Jan 2025

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication verification.

    Published: 14 Jun 2024
    8.2
    High

    CVE-2024-37367

    Last Modified: 21 Nov 2024

    A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.

    Published: 14 Jun 2024
    —
    Unknown

    CVE-2024-38352

    Last Modified: 19 Jun 2024

    CVE was assigned in error.

    Published: 14 Jun 2024
    6.8
    Medium

    CVE-2024-5731

    Last Modified: 15 Apr 2026

    A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating the parameter, thereby leveraging sensitive information.

    Published: 14 Jun 2024
    9.8
    Critical

    CVE-2024-5671

    Last Modified: 15 Apr 2026

    Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.

    Published: 14 Jun 2024
    8.8
    High

    CVE-2024-2024

    Last Modified: 15 Apr 2026

    The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 14 Jun 2024
    4.3
    Medium

    CVE-2024-2023

    Last Modified: 15 Apr 2026

    The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function. This makes it possible for authenticated attackers, with author access and above, to upload files to arbitrary locations on the server.

    Published: 14 Jun 2024
    8.4
    High

    CVE-2024-36459

    Last Modified: 15 Apr 2026

    A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.

    Published: 14 Jun 2024
    4.3
    Medium

    CVE-2023-51376

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

    Published: 14 Jun 2024
    7.6
    High

    CVE-2024-5685

    Last Modified: 21 Nov 2024

    Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.

    Published: 14 Jun 2024
    4.4
    Medium

    CVE-2024-34012

    Last Modified: 21 Nov 2024

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

    Published: 14 Jun 2024
    9.1
    Critical

    CVE-2024-2472

    Last Modified: 8 Apr 2026

    The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for unauthenticated attackers to view other customer's cabinets, including the ability to view PII such as email addresses and to change their LatePoint user password, which may or may not be associated with a WordPress account.

    Published: 14 Jun 2024
    9.8
    Critical

    CVE-2024-3912

    Last Modified: 15 Apr 2026

    Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.

    Published: 14 Jun 2024
    4.7
    Medium

    CVE-2024-37182

    Last Modified: 21 Nov 2024

    Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.

    Published: 14 Jun 2024
    3.8
    Low

    CVE-2024-36287

    Last Modified: 21 Nov 2024

    Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

    Published: 14 Jun 2024
    6.4
    Medium

    CVE-2024-4863

    Last Modified: 8 Apr 2026

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter in all versions up to, and including, 3.2.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Jun 2024
    5.5
    Medium

    CVE-2024-25142

    Last Modified: 20 Mar 2025

    Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

    Published: 14 Jun 2024
    —
    Unknown

    CVE-2024-5996

    Last Modified: 14 Aug 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Jun 2024
    5.3
    Medium

    CVE-2024-5961

    Last Modified: 15 Apr 2026

    Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31 through 7.6.4.

    Published: 14 Jun 2024
    9.8
    Critical

    CVE-2024-5577

    Last Modified: 15 Apr 2026

    The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter of the /system/include/include_user.php file. This makes it possible for unauthenticated attackers to include and execute arbitrary files hosted on external servers, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution. This requires allow_url_include to be set to true in order to exploit, which is not commonly enabled.

    Published: 14 Jun 2024
    5.9
    Medium

    CVE-2024-5465

    Last Modified: 21 Nov 2024

    Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 14 Jun 2024
    4
    Medium

    CVE-2024-5464

    Last Modified: 21 Nov 2024

    Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 14 Jun 2024
    7.3
    High

    CVE-2024-36503

    Last Modified: 21 Nov 2024

    Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 14 Jun 2024
    7.9
    High

    CVE-2024-36502

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 14 Jun 2024
    5.6
    Medium

    CVE-2024-36501

    Last Modified: 21 Nov 2024

    Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

    Published: 14 Jun 2024
    7.8
    High

    CVE-2024-36500

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 14 Jun 2024
    8.8
    High

    CVE-2024-5995

    Last Modified: 15 Apr 2026

    The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.

    Published: 14 Jun 2024
    6.8
    Medium

    CVE-2024-36499

    Last Modified: 21 Nov 2024

    Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 14 Jun 2024
    6.4
    Medium

    CVE-2024-5994

    Last Modified: 8 Apr 2026

    The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Version 9.0.39 adds a caution to make administrators aware of the possibility for abuse if permissions are granted to lower-level users.

    Published: 14 Jun 2024
    7.2
    High

    CVE-2024-31163

    Last Modified: 15 Apr 2026

    ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

    Published: 14 Jun 2024
    7.2
    High

    CVE-2024-31162

    Last Modified: 15 Apr 2026

    The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

    Published: 14 Jun 2024
    6.1
    Medium

    CVE-2024-5155

    Last Modified: 6 Jun 2025

    The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 14 Jun 2024
    4.3
    Medium

    CVE-2024-4751

    Last Modified: 11 Jul 2025

    The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 14 Jun 2024
    6.1
    Medium

    CVE-2024-4480

    Last Modified: 13 May 2025

    The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 14 Jun 2024
    4.6
    Medium

    CVE-2024-4271

    Last Modified: 13 May 2025

    The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

    Published: 14 Jun 2024
    5.4
    Medium

    CVE-2024-4270

    Last Modified: 24 Mar 2025

    The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

    Published: 14 Jun 2024
    4.8
    Medium

    CVE-2024-4005

    Last Modified: 13 Mar 2025

    The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 14 Jun 2024
    4.6
    Medium

    CVE-2024-3993

    Last Modified: 13 May 2025

    The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 14 Jun 2024
    4.8
    Medium

    CVE-2024-3992

    Last Modified: 25 Mar 2025

    The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 14 Jun 2024
    5.4
    Medium

    CVE-2024-3978

    Last Modified: 21 Nov 2024

    The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 14 Jun 2024
    4.8
    Medium

    CVE-2024-3977

    Last Modified: 21 Nov 2024

    The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 14 Jun 2024