CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-34826

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Saleswonder Team: Tobias CF7 WOW Styler cf7-styler.This issue affects CF7 WOW Styler: from n/a through <= 1.6.4.

    Published: 11 Jun 2024
    6.5
    Medium

    CVE-2024-34820

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in If So Plugin If-So Dynamic Content Personalization.This issue affects If-So Dynamic Content Personalization: from n/a through 1.7.1.

    Published: 11 Jun 2024
    8.6
    High

    CVE-2024-24703

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-32148

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-37296

    Last Modified: 15 Apr 2026

    The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-35168

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.

    Published: 11 Jun 2024
    7.2
    High

    CVE-2024-37295

    Last Modified: 15 Apr 2026

    Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.04.5, a user with administrative privileges can upload files that look like images but contain PHP code which can then be executed in the context of the web server. Version 2024.04.5 fixes the issue.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2023-51498

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Woo WooCommerce Canada Post Shipping.This issue affects WooCommerce Canada Post Shipping: from n/a through 2.8.3.

    Published: 11 Jun 2024
    7.5
    High

    CVE-2024-26010

    Last Modified: 27 Aug 2025

    A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specially crafted packets.

    Published: 11 Jun 2024
    1.8
    Low

    CVE-2024-21754

    Last Modified: 27 Aug 2025

    A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may allow a privileged attacker with super-admin profile and CLI access to decrypting the backup file.

    Published: 11 Jun 2024
    6.5
    Medium

    CVE-2023-23775

    Last Modified: 21 Jan 2025

    Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.

    Published: 11 Jun 2024
    6.7
    Medium

    CVE-2023-46720

    Last Modified: 27 Aug 2025

    A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.

    Published: 11 Jun 2024
    6.8
    Medium

    CVE-2024-23111

    Last Modified: 27 Aug 2025

    An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reboot page may allow a remote privileged attacker with super-admin access to execute JavaScript code via crafted HTTP GET requests.

    Published: 11 Jun 2024
    7.8
    High

    CVE-2024-23110

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-31495

    Last Modified: 2 Jan 2025

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-35628

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.

    Published: 11 Jun 2024
    5.4
    Medium

    CVE-2024-35663

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0.

    Published: 11 Jun 2024
    5.5
    Medium

    CVE-2024-37294

    Last Modified: 15 Apr 2026

    Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive a patch.

    Published: 11 Jun 2024
    6.5
    Medium

    CVE-2023-52199

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35665

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in namithjawahar Insert Post Ads.This issue affects Insert Post Ads: from n/a through 1.3.2.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35667

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.

    Published: 11 Jun 2024
    4
    Medium

    CVE-2024-37161

    Last Modified: 4 Sept 2025

    MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerabilities. Version 1.10.1-lts fixes this issue.

    Published: 11 Jun 2024
    4.4
    Medium

    CVE-2024-35235

    Last Modified: 26 Sept 2025

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.

    Published: 11 Jun 2024
    5.7
    Medium

    CVE-2024-28023

    Last Modified: 15 Apr 2026

    A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

    Published: 11 Jun 2024
    6.4
    Medium

    CVE-2024-5189

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-35671

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35683

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.

    Published: 11 Jun 2024
    5.4
    Medium

    CVE-2023-52183

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-34442

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.

    Published: 11 Jun 2024
    7.4
    High

    CVE-2024-28021

    Last Modified: 21 Nov 2024

    A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.

    Published: 11 Jun 2024
    8.6
    High

    CVE-2024-2011

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy

    Published: 11 Jun 2024
    9.1
    Critical

    CVE-2024-2012

    Last Modified: 21 Nov 2024

    vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

    Published: 11 Jun 2024
    10
    Critical

    CVE-2024-2013

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-2461

    Last Modified: 15 Apr 2026

    If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible

    Published: 11 Jun 2024
    6.8
    Medium

    CVE-2024-2462

    Last Modified: 15 Apr 2026

    Allow attackers to intercept or falsify data exchanges between the client and the server

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5701

    Last Modified: 3 Apr 2025

    Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5699

    Last Modified: 4 Apr 2025

    In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    6.1
    Medium

    CVE-2024-5698

    Last Modified: 14 Mar 2025

    By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-5697

    Last Modified: 13 Mar 2025

    A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5695

    Last Modified: 21 Nov 2024

    If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    7.5
    High

    CVE-2024-5694

    Last Modified: 14 Mar 2025

    An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-5689

    Last Modified: 21 Nov 2024

    In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-5687

    Last Modified: 27 Mar 2025

    If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    8.5
    High

    CVE-2024-36266

    Last Modified: 26 Sept 2025

    A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining administrative privileges for the managed remote devices.

    Published: 11 Jun 2024
    7.3
    High

    CVE-2024-35303

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while parsing specially crafted MODEL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22958)

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-35292

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (All versions). Affected devices are using a predictable IP ID sequence number. This leaves the system susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack and eventually could allow an attacker to create a denial of service condition.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-35212

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.

    Published: 11 Jun 2024
    6.8
    Medium

    CVE-2024-35211

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).

    Published: 11 Jun 2024
    5.1
    Medium

    CVE-2024-35210

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-35209

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.

    Published: 11 Jun 2024