CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-5757

    Last Modified: 8 Apr 2026

    The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-2098

    Last Modified: 8 Apr 2026

    The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

    Published: 13 Jun 2024
    10
    Critical

    CVE-2024-3922

    Last Modified: 8 Apr 2026

    The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 13 Jun 2024
    2.7
    Low

    CVE-2024-5967

    Last Modified: 15 Apr 2026

    A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console or compromised a user with sufficient privileges can leak domain credentials and attack the domain.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-36588

    Last Modified: 15 Apr 2026

    An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

    Published: 13 Jun 2024
    4.5
    Medium

    CVE-2023-52890

    Last Modified: 15 Apr 2026

    NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challenging.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-36760

    Last Modified: 15 Apr 2026

    A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : _ $LT $impl $u20 $rhai.. engine.. Engine$GT$::eval_stmt::h3f1d68ce37fc6e96). Due to the stack overflow is a recursive call/SRC/rhai/SRC/eval/STMT. Rs file eval_stmt_block function.

    Published: 13 Jun 2024
    5.7
    Medium

    CVE-2024-5953

    Last Modified: 15 Apr 2026

    A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.

    Published: 13 Jun 2024
    6.1
    Medium

    CVE-2023-35859

    Last Modified: 17 Mar 2025

    A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multiple parameters.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-38295

    Last Modified: 13 Mar 2025

    ALCASAR before 3.6.1 allows still_connected.php remote code execution.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-38294

    Last Modified: 13 Mar 2025

    ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.

    Published: 13 Jun 2024
    9.6
    Critical

    CVE-2024-38293

    Last Modified: 18 Jun 2025

    ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-37631

    Last Modified: 3 Apr 2025

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

    Published: 13 Jun 2024
    5.5
    Medium

    CVE-2024-37877

    Last Modified: 15 Apr 2026

    UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp and in function DecodeRlsMessage in src/lib/rls/rls_pdu.cpp

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-31777

    Last Modified: 18 Jun 2025

    File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

    Published: 13 Jun 2024
    8.4
    High

    CVE-2024-32504

    Last Modified: 13 Mar 2025

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper length checking, which can result in an OOB (Out-of-Bounds) Write vulnerability.

    Published: 13 Jun 2024
    5.3
    Medium

    CVE-2023-35858

    Last Modified: 18 Jun 2025

    XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

    Published: 13 Jun 2024
    5.3
    Medium

    CVE-2023-35860

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.

    Published: 13 Jun 2024
    8.4
    High

    CVE-2024-31956

    Last Modified: 14 Mar 2025

    An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-33253

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title and description fields of the badge template editing function.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-35325

    Last Modified: 28 Aug 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-35326

    Last Modified: 28 Aug 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Jun 2024
    7.5
    High

    CVE-2024-35328

    Last Modified: 28 Aug 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-36586

    Last Modified: 15 Apr 2026

    An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.

    Published: 13 Jun 2024
    7.8
    High

    CVE-2024-36587

    Last Modified: 15 Apr 2026

    Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

    Published: 13 Jun 2024
    4.3
    Medium

    CVE-2024-36589

    Last Modified: 15 Apr 2026

    An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.

    Published: 13 Jun 2024
    5.4
    Medium

    CVE-2024-36647

    Last Modified: 18 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-37630

    Last Modified: 29 May 2025

    D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-37632

    Last Modified: 13 Mar 2025

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

    Published: 13 Jun 2024
    8.8
    High

    CVE-2024-37633

    Last Modified: 3 Apr 2025

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-37634

    Last Modified: 3 Apr 2025

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-37635

    Last Modified: 21 Nov 2024

    TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

    Published: 13 Jun 2024
    9.8
    Critical

    CVE-2024-37849

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

    Published: 13 Jun 2024
    6.5
    Medium

    CVE-2024-1963

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

    Published: 12 Jun 2024
    4.4
    Medium

    CVE-2024-4201

    Last Modified: 21 Nov 2024

    A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

    Published: 12 Jun 2024
    8.4
    High

    CVE-2024-3468

    Last Modified: 15 Apr 2026

    There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.

    Published: 12 Jun 2024
    7
    High

    CVE-2024-3467

    Last Modified: 21 Nov 2024

    There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

    Published: 12 Jun 2024
    —
    Unknown

    CVE-2024-5934

    Last Modified: 14 Jun 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Jun 2024
    —
    Unknown

    CVE-2024-5927

    Last Modified: 13 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-1736

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-1495

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. It was possible for an attacker to cause a denial of service using maliciously crafted file.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2023-29267

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287612.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-31881

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user. IBM X-Force ID: 287613.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-28762

    Last Modified: 4 Nov 2025

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-5559

    Last Modified: 21 Nov 2024

    CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.

    Published: 12 Jun 2024
    7.8
    High

    CVE-2024-2747

    Last Modified: 21 Nov 2024

    CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.

    Published: 12 Jun 2024
    —
    Unknown

    CVE-2024-2230

    Last Modified: 12 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2024-37040

    Last Modified: 21 Nov 2024

    CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.

    Published: 12 Jun 2024
    5.9
    Medium

    CVE-2024-37039

    Last Modified: 21 Nov 2024

    CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

    Published: 12 Jun 2024
    7.5
    High

    CVE-2024-37038

    Last Modified: 21 Nov 2024

    CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

    Published: 12 Jun 2024