CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-37037

    Last Modified: 21 Nov 2024

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.

    Published: 12 Jun 2024
    9.8
    Critical

    CVE-2024-37036

    Last Modified: 21 Nov 2024

    CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-5560

    Last Modified: 21 Nov 2024

    CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-5898

    Last Modified: 21 Nov 2024

    A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268142 is the identifier assigned to this vulnerability.

    Published: 12 Jun 2024
    6.8
    Medium

    CVE-2024-5909

    Last Modified: 21 Nov 2024

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

    Published: 12 Jun 2024
    4.5
    Medium

    CVE-2024-5557

    Last Modified: 21 Nov 2024

    CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.

    Published: 12 Jun 2024
    5.5
    Medium

    CVE-2024-5908

    Last Modified: 21 Nov 2024

    A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.

    Published: 12 Jun 2024
    5.2
    Medium

    CVE-2024-5907

    Last Modified: 21 Nov 2024

    A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-5558

    Last Modified: 21 Nov 2024

    CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.

    Published: 12 Jun 2024
    4.8
    Medium

    CVE-2024-5906

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.

    Published: 12 Jun 2024
    2
    Low

    CVE-2024-5905

    Last Modified: 21 Nov 2024

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2024-5759

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges

    Published: 12 Jun 2024
    6.9
    Medium

    CVE-2024-5897

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268141 was assigned to this vulnerability.

    Published: 12 Jun 2024
    3.5
    Low

    CVE-2024-1891

    Last Modified: 21 Nov 2024

    A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.

    Published: 12 Jun 2024
    6.9
    Medium

    CVE-2024-5896

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268140.

    Published: 12 Jun 2024
    8.1
    High

    CVE-2024-37300

    Last Modified: 15 Apr 2026

    OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take precedence over `identity_provider`. Since JupyterHub 5.0, `allow_all` does take precedence over `identity_provider`. On a hub with the same config, now all users will be allowed to login, regardless of `identity_provider`. `identity_provider` will basically be ignored. This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. OAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. As a workaround, do not upgrade to JupyterHub 5.0 when using `GlobusOAuthenticator` in the prior configuration.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2024-37297

    Last Modified: 21 Nov 2024

    WooCommerce is an open-source e-commerce platform built on WordPress. A vulnerability introduced in WooCommerce 8.8 allows for cross-site scripting. A bad actor can manipulate a link to include malicious HTML & JavaScript content. While the content is not saved to the database, the links may be sent to victims for malicious purposes. The injected JavaScript could hijack content & data stored in the browser, including the session. The URL content is read through the `Sourcebuster.js` library and then inserted without proper sanitization to the classic checkout and registration forms. Versions 8.8.5 and 8.9.3 contain a patch for the issue. As a workaround, one may disable the Order Attribution feature.

    Published: 12 Jun 2024
    7.8
    High

    CVE-2024-28964

    Last Modified: 21 Nov 2024

    Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.

    Published: 12 Jun 2024
    6.2
    Medium

    CVE-2024-2300

    Last Modified: 15 Apr 2026

    HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-5895

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268139.

    Published: 12 Jun 2024
    6.9
    Medium

    CVE-2024-5894

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-268138 is the identifier assigned to this vulnerability.

    Published: 12 Jun 2024
    7.1
    High

    CVE-2024-34065

    Last Modified: 21 Nov 2024

    Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and retrieve the 3rd party tokens. The attack requires user interaction (one click). Unauthenticated attackers can leverage two vulnerabilities to obtain an 3rd party token and the bypass authentication of Strapi apps. Users should upgrade @strapi/plugin-users-permissions to version 4.24.2 to receive a patch.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-31217

    Last Modified: 21 Nov 2024

    Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and production environments. Usually, errors in the application cause it to log the error and keep it running for other clients. This behavior, in contrast, stops the server execution, making it unavailable for any clients until it's manually restarted. Any user with access to the file upload functionality is able to exploit this vulnerability, affecting applications running in both development mode and production mode as well. Users should upgrade @strapi/plugin-upload to version 4.22.0 to receive a patch.

    Published: 12 Jun 2024
    2.3
    Low

    CVE-2024-29181

    Last Modified: 21 Nov 2024

    Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-5893

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268137 was assigned to this vulnerability.

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-37304

    Last Modified: 4 Sept 2025

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allows attackers to exploit autolinks as a vector for Cross-Site Scripting (XSS) attacks. When a user inputs a Markdown autolink such as `<javascript:alert(1)>`, the link is rendered without proper sanitization. This means that the JavaScript code within the autolink can be executed by the browser, leading to an XSS attack. Version 2024.05.28 contains a patch for this issue.

    Published: 12 Jun 2024
    9.8
    Critical

    CVE-2024-36265

    Last Modified: 14 Jul 2026

    ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST requests. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 12 Jun 2024
    9.8
    Critical

    CVE-2024-36264

    Last Modified: 20 Mar 2025

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 12 Jun 2024
    8.1
    High

    CVE-2024-36263

    Last Modified: 15 Jul 2025

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 12 Jun 2024
    7.8
    High

    CVE-2024-0865

    Last Modified: 21 Nov 2024

    CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

    Published: 12 Jun 2024
    8.8
    High

    CVE-2024-25949

    Last Modified: 21 Nov 2024

    Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privileges.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-5313

    Last Modified: 21 Nov 2024

    CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts are limited to port scanning and fingerprinting activities as well as attempts to perform a potential denial of service attack on the exposed SSH interface.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-5056

    Last Modified: 21 Nov 2024

    CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.

    Published: 12 Jun 2024
    7.2
    High

    CVE-2024-5211

    Last Modified: 15 Jul 2025

    A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anythingllm.db' database file and other files stored in the 'storage' directory, such as internal communication keys and .env secrets. Exploitation of this vulnerability could lead to application compromise, denial of service (DoS) attacks, and unauthorized admin account takeover. The issue stems from improper validation of user-supplied input in the process of setting a custom logo for the app, which can be manipulated to achieve arbitrary file read, deletion, or overwrite, and to execute a DoS attack by deleting critical files required for the application's operation.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-5674

    Last Modified: 8 Apr 2026

    The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers. This issue affects only sites running the PHP version below 8.0

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-3492

    Last Modified: 8 Apr 2026

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    4.4
    Medium

    CVE-2024-1766

    Last Modified: 8 Apr 2026

    The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.

    Published: 12 Jun 2024
    9.8
    Critical

    CVE-2024-4898

    Last Modified: 8 Apr 2026

    The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

    Published: 12 Jun 2024
    —
    Unknown

    CVE-2024-5900

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2023-40209

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2023-40603

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2023-41240

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

    Published: 12 Jun 2024
    9.3
    Critical

    CVE-2024-1659

    Last Modified: 21 Nov 2024

    Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-44234

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

    Published: 12 Jun 2024
    9.3
    Critical

    CVE-2024-1577

    Last Modified: 21 Nov 2024

    Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.

    Published: 12 Jun 2024
    9.3
    Critical

    CVE-2024-1576

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-25030

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2023-38395

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2023-40672

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2024-2092

    Last Modified: 8 Apr 2026

    The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024