CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2024-35235

    Last Modified: 26 Sept 2025

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target. Given that cupsd is often running as root, this can result in the change of permission of any user or system files to be world writable. Given the aforementioned Ubuntu AppArmor context, on such systems this vulnerability is limited to those files modifiable by the cupsd process. In that specific case it was found to be possible to turn the configuration of the Listen argument into full control over the cupsd.conf and cups-files.conf configuration files. By later setting the User and Group arguments in cups-files.conf, and printing with a printer configured by PPD with a `FoomaticRIPCommandLine` argument, arbitrary user and group (not root) command execution could be achieved, which can further be used on Ubuntu systems to achieve full root command execution. Commit ff1f8a623e090dee8a8aadf12a6a4b25efac143d contains a patch for the issue.

    Published: 11 Jun 2024
    5.7
    Medium

    CVE-2024-28023

    Last Modified: 15 Apr 2026

    A vulnerability exists in the message queueing mechanism that if exploited can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with sensitive information or even execute arbitrary code.

    Published: 11 Jun 2024
    6.4
    Medium

    CVE-2024-5189

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_js’ parameter in all versions up to, and including, 5.9.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-35671

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35683

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Teplitsa of social technologies Leyka.This issue affects Leyka: from n/a through 3.31.1.

    Published: 11 Jun 2024
    5.4
    Medium

    CVE-2023-52183

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-34442

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.

    Published: 11 Jun 2024
    7.4
    High

    CVE-2024-28021

    Last Modified: 21 Nov 2024

    A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.

    Published: 11 Jun 2024
    8.6
    High

    CVE-2024-2011

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy

    Published: 11 Jun 2024
    9.1
    Critical

    CVE-2024-2012

    Last Modified: 21 Nov 2024

    vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

    Published: 11 Jun 2024
    10
    Critical

    CVE-2024-2013

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-2461

    Last Modified: 15 Apr 2026

    If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible

    Published: 11 Jun 2024
    6.8
    Medium

    CVE-2024-2462

    Last Modified: 15 Apr 2026

    Allow attackers to intercept or falsify data exchanges between the client and the server

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5701

    Last Modified: 3 Apr 2025

    Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5699

    Last Modified: 4 Apr 2025

    In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    6.1
    Medium

    CVE-2024-5698

    Last Modified: 14 Mar 2025

    By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-5697

    Last Modified: 13 Mar 2025

    A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    9.8
    Critical

    CVE-2024-5695

    Last Modified: 21 Nov 2024

    If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    7.5
    High

    CVE-2024-5694

    Last Modified: 14 Mar 2025

    An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-5689

    Last Modified: 21 Nov 2024

    In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-5687

    Last Modified: 27 Mar 2025

    If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potential for incorrect security checks within the browser in addition to incorrect or misleading information sent to remote websites. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 127.

    Published: 11 Jun 2024
    8.5
    High

    CVE-2024-36266

    Last Modified: 26 Sept 2025

    A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining administrative privileges for the managed remote devices.

    Published: 11 Jun 2024
    7.3
    High

    CVE-2024-35303

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while parsing specially crafted MODEL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22958)

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-35292

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (All versions). Affected devices are using a predictable IP ID sequence number. This leaves the system susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as their base method of attack and eventually could allow an attacker to create a denial of service condition.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-35212

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.

    Published: 11 Jun 2024
    6.8
    Medium

    CVE-2024-35211

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).

    Published: 11 Jun 2024
    5.1
    Medium

    CVE-2024-35210

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2024-35209

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.

    Published: 11 Jun 2024
    4.8
    Medium

    CVE-2024-35208

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.

    Published: 11 Jun 2024
    8.5
    High

    CVE-2024-35207

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.

    Published: 11 Jun 2024
    8.5
    High

    CVE-2024-35206

    Last Modified: 11 Feb 2025

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access.

    Published: 11 Jun 2024
    7.4
    High

    CVE-2024-33500

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.

    Published: 11 Jun 2024
    6.9
    Medium

    CVE-2023-50763

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.3), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of affected products, if configured to allow the import of PKCS12 containers, could end up in an infinite loop when processing incomplete certificate chains. This could allow an authenticated remote attacker to create a denial of service condition by importing specially crafted PKCS12 containers.

    Published: 11 Jun 2024
    4.8
    Medium

    CVE-2023-38533

    Last Modified: 21 Aug 2025

    A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35685

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Anders Norén Radcliffe 2.This issue affects Radcliffe 2: from n/a through 2.0.17.

    Published: 11 Jun 2024
    5.4
    Medium

    CVE-2023-52179

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-34813

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-5829

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is an unknown functionality of the component avueUeditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-267895. NOTE: The code maintainer explains, that "rich text is no longer maintained".

    Published: 11 Jun 2024
    —
    Unknown

    CVE-2024-5850

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jun 2024
    6.4
    Medium

    CVE-2024-5584

    Last Modified: 15 Apr 2026

    The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with the staff member role and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2024-34824

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2023-52217

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

    Published: 11 Jun 2024
    5.4
    Medium

    CVE-2024-24704

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a through 3.3.3.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2023-52186

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.2.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2024-35692

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.

    Published: 11 Jun 2024
    6.5
    Medium

    CVE-2024-35716

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.9.

    Published: 11 Jun 2024
    4.3
    Medium

    CVE-2023-33922

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

    Published: 11 Jun 2024
    5.3
    Medium

    CVE-2023-28775

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.

    Published: 11 Jun 2024
    8.3
    High

    CVE-2023-25799

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

    Published: 11 Jun 2024
    6.4
    Medium

    CVE-2024-5531

    Last Modified: 15 Apr 2026

    The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Jun 2024